VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25452 CVEsRSS

CVE-2026-87909High· 7.5
1w ago

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into a…

▾ Twilightopajaap · WP Photo Album PlusEPSS 0.91%via NVD
CVE-2026-15660Medium· 4.3
1w ago

The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7

The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is due to a missing capability check on the handle_oauth_callback() function which is hooked to admin_init and proc…

▾ Sunlitcleverplugins · SEO BoosterEPSS 0.20%via NVD
CVE-2026-92229Critical· 9.1PoC
1w ago

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2

The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to e…

▾ Abyssalwpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form BuilderEPSS 0.73%via NVD
CVE-2026-89333Medium· 6.5
1w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.0.8 via the 'student_id' parameter due to missing validation on a user co…

▾ Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.46%via NVD
CVE-2026-84434Critical· 9.8PoC
1w ago

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persis…

▾ AbyssalGravity Forms · Gravity FormsEPSS 3.9%via NVD
CVE-2026-15760Medium· 6.5
1w ago

The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX actions

The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX actions. The handlers only conditionally …

▾ SunlitDivi Essential · Divi EssentialsEPSS 0.22%via NVD
CVE-2026-13354High· 7.2
1w ago

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This ma…

▾ Twilightgabelivan · Asset CleanUp: Page Speed BoosterEPSS 0.24%via NVD
CVE-2026-89093Medium· 5.3
1w ago

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in all versions up to, and including, 2.15.33. This is due to the `is_ai_bot_user()` fun…

▾ Sunlitwordplus · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsEPSS 0.56%via NVD
CVE-2026-89081Medium· 6.1
1w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and o…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions up to, and including, 4.0.8 due to insufficient input sanitization and o…

▾ Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.38%via NVD
CVE-2026-92807High· 8.8
1w ago

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies…

▾ Twilightpdfcrowd · Save as PDF Plugin by PDFCrowdEPSS 0.46%via NVD
CVE-2026-89334Medium· 6.5
1w ago

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.15.33. This is due to the plugin not properly verifying that…

▾ Sunlitwordplus · Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat BotsEPSS 0.70%via NVD
CVE-2026-88944Medium· 4.3
1w ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. This is due to the plugin not properly verifying that a user is authorized to pe…

▾ Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.46%via NVD
CVE-2026-92967Medium· 6.1
1w ago

The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and including, 1.20.2

The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and including, 1.20.2. This is due to insufficient output escaping , which reads $_GET['keyword'], applies on…

▾ Sunlitwppochipp · PochippEPSS 0.38%via NVD
CVE-2026-12042Medium· 4.4
1w ago

The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping

The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping. This makes it possib…

▾ Sunlitf1logic · WP2Social Auto PublishEPSS 0.21%via NVD
CVE-2026-77820Medium· 6.4
1w ago

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization and output escaping

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to insufficient input sanitization and output escaping. This makes it poss…

▾ Sunlitstellarwp · WPCompleteEPSS 0.33%via NVD
CVE-2026-93922High· 8.8PoC
1w ago

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that exec…

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.82%via NVD
CVE-2026-93923High· 8.8PoC
1w ago

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject maliciou…

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.60%via NVD
CVE-2026-93921Medium· 4.3PoC
1w ago

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call the endpoint with type=8 and crafted content to read bl…

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via NVD
CVE-2026-77875Medium· 6.8
1w ago

The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary

The application protects access through its calculator-style vault passcode, but the stored data is not bound to that authentication boundary. A local actor who can access shared external storage, such as through an authorized non-root A…

▾ SunlitQUANTUMTECH LTD · Hide Photos - Secure vaultEPSS 0.18%via NVD
CVE-2026-75885Critical· 9.3
1w ago

A flaw was found in the OpenShift console

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF)…

▾ MidnightRed Hat · openshift4/ose-consoleEPSS 0.53%via NVD
CVE-2026-93740Critical· 10.0PoC
1w ago

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046

A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is possible to initi…

▾ AbyssalTotolink · A3002MUEPSS 0.88%via NVD
CVE-2026-93739Critical· 9.9PoC
1w ago

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046

A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be per…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2026-93738Critical· 9.9PoC
1w ago

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046

A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attack is possibl…

▾ AbyssalTotolink · A3002MUEPSS 0.85%via NVD
CVE-2026-88097High· 8.1
1w ago

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · edge_chromiumEPSS 0.26%via NVD
CVE-2026-57228High· 8.2
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a hea…

▾ TwilightOISF · suricataEPSS 0.57%via NVD
CVE-2026-63449Low· 3.7
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SIP parser in rust/src/sip/parser.rs stores request and response body lengths in 16-bit fie…

▾ Sunlitoisf · suricatavia NVD
CVE-2026-93574Medium· 6.5
1w ago

A flaw was found in Netty's `netty-codec-http` component

A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chun…

▾ SunlitRed Hat · netty-codec-httpEPSS 0.86%via NVD
CVE-2026-93562Medium· 6.5PoC
1w ago

A flaw was found in Netty's HTTP/1 decoder

A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbit…

▾ TwilightRed Hat · netty-codec-httpEPSS 0.58%via NVD
CVE-2026-63450Low· 3.7
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiatio…

▾ Sunlitoisf · suricatavia NVD
CVE-2026-57227High· 7.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages …

▾ TwilightOISF · suricataEPSS 0.70%via NVD
CVEs tagged “nvd” — page 112 · VulnSea