NIST

CVE intelligence

Cached from NVD. 2026-09-19 PT. Recent.

CVETitleVendorPublishedCVSSKEV listed
CVE-2026-75586The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in al2026-09-05
CVE-2026-75018The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due 2026-09-05
CVE-2026-67281RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uni2026-09-05
CVE-2026-67279RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an 2026-09-05
CVE-2026-67278MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH2026-09-05
CVE-2026-67277MikroTik RouterOS Missing Authentication for Critical Function VulnerabilityMikrotik2026-09-052026-09-10
CVE-2026-67276RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the ke2026-09-05
CVE-2026-6554libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it 2026-09-05
CVE-2026-6244libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular unc2026-09-05
CVE-2026-52777YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImport2026-09-05
CVE-2026-52775YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vuln2026-09-05
CVE-2026-52774YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attr2026-09-05
CVE-2026-52773YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET 2026-09-05
CVE-2026-52772YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.2026-09-05
CVE-2026-52771YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag ret2026-09-05
CVE-2026-52770YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated2026-09-05
CVE-2026-52769YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - expose2026-09-05
CVE-2026-52767YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the resu2026-09-05
CVE-2026-52766YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.2026-09-05
CVE-2026-52763YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argum2026-09-05
CVE-2026-52762YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulne2026-09-05
CVE-2026-4361The Divi theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.27.6. This is due to the `2026-09-05
CVE-2026-3853The Divi theme for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the `image_src` attribute of the `et_pb_video_slider2026-09-05
CVE-2026-31912libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a ju2026-09-05
CVE-2026-31911libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a craf2026-09-05
CVE-2026-19887The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deseriali2026-09-05
CVE-2026-19861The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value 2026-09-05
CVE-2026-19858The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving reques2026-09-05
CVE-2026-19769The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeate2026-09-05
CVE-2026-18843The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' no2026-09-05
CVE-2026-18406The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scriptin2026-09-05
CVE-2026-18404The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attr2026-09-05
CVE-2026-18313rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it2026-09-05
CVE-2026-18238The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious serv2026-09-05
CVE-2026-16649The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and inc2026-09-05
CVE-2026-15984The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and includ2026-09-05
CVE-2026-15550The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This i2026-09-05
CVE-2026-15247The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one 2026-09-05
CVE-2026-14975The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteur2026-09-05
CVE-2026-13447The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is 2026-09-05

Previous161–200 of 210Next