Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51159
Total
4081
Critical
15166
High
14812
Medium
CVE ID Severity Score Description Published
CVE-2026-44387 MEDIUM 5.2 ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may … Jul 28, 2026
CVE-2026-15267 MEDIUM 6.5 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_filter' parameter in … Jul 28, 2026
CVE-2026-14516 HIGH 7.5 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' parameter in all versions … Jul 28, 2026
CVE-2026-14171 MEDIUM 6.1 An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can … Jul 28, 2026
CVE-2026-14170 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 28, 2026
CVE-2026-14169 HIGH 8.1 Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing user passwords which could … Jul 28, 2026
CVE-2026-14168 HIGH 8.8 A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulting in gaining full … Jul 28, 2026
CVE-2026-14167 HIGH 8.8 A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management due to incorrect authorization. Jul 28, 2026
CVE-2026-13161 HIGH 7.5 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_user]' parameter in all versions up … Jul 28, 2026
CVE-2026-12800 HIGH 7.5 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST … Jul 28, 2026
CVE-2026-55977 LOW 3.3 Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code … Jul 28, 2026
CVE-2026-15730 MEDIUM 6.4 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' … Jul 28, 2026
CVE-2026-15673 MEDIUM 4.4 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via … Jul 28, 2026
CVE-2026-15671 MEDIUM 4.9 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via … Jul 28, 2026
CVE-2026-15670 MEDIUM 4.9 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to time-based SQL Injection via … Jul 28, 2026
CVE-2026-15014 CRITICAL 9.8 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to … Jul 28, 2026
CVE-2026-12741 HIGH 7.5 The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in … Jul 28, 2026
CVE-2026-11756 CRITICAL 10.0 A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an … Jul 28, 2026
CVE-2024-14041 UNKNOWN — In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes … Jul 28, 2026
CVE-2026-6251 MEDIUM 6.5 The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due to … Jul 28, 2026
CVE-2026-16811 MEDIUM 4.9 The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all … Jul 28, 2026
CVE-2026-16797 MEDIUM 4.3 The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, … Jul 28, 2026
CVE-2026-16587 MEDIUM 4.3 The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … Jul 28, 2026
CVE-2026-16585 HIGH 7.2 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to … Jul 28, 2026
CVE-2026-15136 MEDIUM 4.3 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … Jul 28, 2026