Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51159
Total
4081
Critical
15166
High
14812
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44387 | MEDIUM | 5.2 | ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may … | Jul 28, 2026 |
| CVE-2026-15267 | MEDIUM | 6.5 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in … | Jul 28, 2026 |
| CVE-2026-14516 | HIGH | 7.5 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions … | Jul 28, 2026 |
| CVE-2026-14171 | MEDIUM | 6.1 | An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can … | Jul 28, 2026 |
| CVE-2026-14170 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 28, 2026 |
| CVE-2026-14169 | HIGH | 8.1 | Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could … | Jul 28, 2026 |
| CVE-2026-14168 | HIGH | 8.8 | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full … | Jul 28, 2026 |
| CVE-2026-14167 | HIGH | 8.8 | A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization. | Jul 28, 2026 |
| CVE-2026-13161 | HIGH | 7.5 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up … | Jul 28, 2026 |
| CVE-2026-12800 | HIGH | 7.5 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST … | Jul 28, 2026 |
| CVE-2026-55977 | LOW | 3.3 | Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code … | Jul 28, 2026 |
| CVE-2026-15730 | MEDIUM | 6.4 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' … | Jul 28, 2026 |
| CVE-2026-15673 | MEDIUM | 4.4 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via … | Jul 28, 2026 |
| CVE-2026-15671 | MEDIUM | 4.9 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via … | Jul 28, 2026 |
| CVE-2026-15670 | MEDIUM | 4.9 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to time-based SQL Injection via … | Jul 28, 2026 |
| CVE-2026-15014 | CRITICAL | 9.8 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to … | Jul 28, 2026 |
| CVE-2026-12741 | HIGH | 7.5 | The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in … | Jul 28, 2026 |
| CVE-2026-11756 | CRITICAL | 10.0 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an … | Jul 28, 2026 |
| CVE-2024-14041 | UNKNOWN | — | In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes … | Jul 28, 2026 |
| CVE-2026-6251 | MEDIUM | 6.5 | The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due to … | Jul 28, 2026 |
| CVE-2026-16811 | MEDIUM | 4.9 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all … | Jul 28, 2026 |
| CVE-2026-16797 | MEDIUM | 4.3 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … | Jul 28, 2026 |
| CVE-2026-16587 | MEDIUM | 4.3 | The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … | Jul 28, 2026 |
| CVE-2026-16585 | HIGH | 7.2 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to … | Jul 28, 2026 |
| CVE-2026-15136 | MEDIUM | 4.3 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … | Jul 28, 2026 |