Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51159
Total
4081
Critical
15166
High
14812
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15444 | MEDIUM | 4.9 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions … | Jul 28, 2026 |
| CVE-2026-15411 | MEDIUM | 5.3 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in … | Jul 28, 2026 |
| CVE-2026-15025 | HIGH | 7.5 | The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, … | Jul 28, 2026 |
| CVE-2026-13440 | HIGH | 7.2 | The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting … | Jul 28, 2026 |
| CVE-2026-13110 | MEDIUM | 5.3 | The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing … | Jul 28, 2026 |
| CVE-2026-65880 | UNKNOWN | — | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms … | Jul 28, 2026 |
| CVE-2026-63303 | UNKNOWN | — | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before … | Jul 28, 2026 |
| CVE-2026-63302 | UNKNOWN | — | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary … | Jul 28, 2026 |
| CVE-2026-63301 | UNKNOWN | — | In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API … | Jul 28, 2026 |
| CVE-2026-18029 | UNKNOWN | — | Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and … | Jul 28, 2026 |
| CVE-2026-18028 | UNKNOWN | — | The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in … | Jul 28, 2026 |
| CVE-2026-17072 | LOW | 3.3 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a … | Jul 28, 2026 |
| CVE-2026-65624 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 … | Jul 28, 2026 |
| CVE-2026-59248 | UNKNOWN | — | Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or … | Jul 28, 2026 |
| CVE-2026-58246 | MEDIUM | 4.3 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a … | Jul 28, 2026 |
| CVE-2026-16462 | CRITICAL | 9.8 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands. | Jul 28, 2026 |
| CVE-2026-14785 | HIGH | 7.5 | The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1.7.13 … | Jul 28, 2026 |
| CVE-2026-14328 | HIGH | 8.8 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and … | Jul 28, 2026 |
| CVE-2026-11841 | CRITICAL | 9.4 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A … | Jul 28, 2026 |
| CVE-2026-11598 | MEDIUM | 5.0 | The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including, 1.4.3 due to … | Jul 28, 2026 |
| CVE-2026-10207 | HIGH | 7.5 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficient sanitization … | Jul 28, 2026 |
| CVE-2026-9680 | MEDIUM | 5.8 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on … | Jul 28, 2026 |
| CVE-2026-8167 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Reflected XSS. This issue affects News … | Jul 28, 2026 |
| CVE-2026-61376 | HIGH | 7.2 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS … | Jul 28, 2026 |
| CVE-2026-59764 | HIGH | 7.2 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command … | Jul 28, 2026 |