Tagged “nvd”
CVEs tagged nvd, newest first.
30156 CVEsRSS
CVE-2026-19800Medium· 4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping o…
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping o…
CVE-2026-81647Medium· 5.3Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-49315High· 7.1DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.
DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-11363Medium· 6.6The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.6 via deserialization of untrusted input . This makes it possible for au…
CVE-2026-6485High· 8.2UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVE-2026-87088High· 7.0Tanium addressed an unauthorized code execution vulnerability in Enforce.
Tanium addressed an unauthorized code execution vulnerability in Enforce.
CVE-2026-87075High· 8.1Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87072High· 7.1Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87047Medium· 6.3Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87046Medium· 4.3Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87037Medium· 5.4Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87033Medium· 5.4Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87030High· 8.5Tanium addressed a path traversal vulnerability in Comply.
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-87025Medium· 5.4Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87019Medium· 4.3Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-14892Medium· 4.3Tanium addressed an improper access controls vulnerability in Tanium Server.
Tanium addressed an improper access controls vulnerability in Tanium Server.
CVE-2026-14505Medium· 6.6Tanium addressed a path traversal vulnerability in Tanium Data Service.
Tanium addressed a path traversal vulnerability in Tanium Data Service.
CVE-2026-87084High· 7.7Tanium addressed a server-side request forgery vulnerability in Enforce.
Tanium addressed a server-side request forgery vulnerability in Enforce.
CVE-2026-87073Medium· 6.5Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87048Medium· 5.4Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87036High· 8.1Tanium addressed an improper access controls vulnerability in Comply.
Tanium addressed an improper access controls vulnerability in Comply.
CVE-2026-87034High· 8.3Tanium addressed a SQL injection vulnerability in Comply.
Tanium addressed a SQL injection vulnerability in Comply.
CVE-2026-87023High· 8.5Tanium addressed a path traversal vulnerability in Comply.
Tanium addressed a path traversal vulnerability in Comply.
CVE-2026-76801High· 8.8The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function
The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.1.10 via the value function. This is due to a …
CVE-2026-13359High· 7.2The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to i…
The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter in all versions up to, and including, 1.7.5 due to i…
CVE-2026-12956Medium· 5.3The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint
The WP Event Solution (Eventin) plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 4.1.22 via the create_item() handler for the /wp-json/eventin/v2/orders REST endpoint. The endpoint's create_it…
CVE-2026-13709Medium· 6.4The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sani…
The Graphina – Charts and Graphs For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'iq_tree_tree_chart_template' Widget Setting in all versions up to, and including, 3.1.11 due to insufficient input sani…
CVE-2026-87724Medium· 6.5Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state
Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.
CVE-2026-87083Medium· 5.5A weakness has been identified in tile-ai tilelang up to 0.1.14
A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to …
CVE-2026-87633High· 8.6Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction
Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)