VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
19,982 CVE recordsPage 653 of 1333 · EPSS data 2026.08.13
ReviewCritical
CVE-2026-40750

themagnifico52 Kids Online Store

Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12225

syracom AG Secure Login (2FA) for Jira, Secure Login (2FA) for Confluence, Secure Login (2FA) for Bitbucket

syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass the two-factor authentication flow by sending HTTP requests with a crafted User-Agent header containing specific strings such as AtlassianMobileApp or JIRA. When such a User-Agent is present, the plugin does not enforce the configured 2FA checks for protected web resources. Successful exploitation allows the attacker to access the affected Atlassian application as the compromised user without com...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-10829

Moxa NPort W2150A-W4/W2250A-W4 Series, NPort W2150A/W2250A Series

A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input in the "Server location" parameter on the Basic settings page. An attacker could exploit this vulnerability by sending crafted input to the web service, resulting in memory corruption. Successful exploitation of this vulnerability could allow remote code execution on the target system with root privileges.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-8442

https://wpreviewslider.com/ WP Review Slider Pro

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to missing authorization checks on the wpfb_hide_review and wprp_save_review_admin AJAX handlers combined with insufficient path validation in the wpfb_hidereview_ajax() function, which uses strpos() to check that a stored media URL starts with the expected prefix but fails to sanitize path traversal sequences in the remaining relative path before passing it to unlink(). This makes it possible for authenticated attackers, with subscriber-level access and...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-8176

latepoint LatePoint – Calendar Booking Plugin for Appointments and Events

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 5.5.1. The plugin chains three independent flaws that together allow an authenticated Agent (Agent+) to overwrite a WordPress Administrator's password without ever invoking an Administrator-only API. This makes it possible for authenticated attackers, with Agent access and above, to elevate their privileges to Administrator.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-5416

TURCK TBEN-LL-SE-M2, TBEN-L4-SE-M2, TBEN-L5-SE-M2

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-54191

Pods Framework Pods

CVE-2026-54191 affects Pods Framework Pods. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-52715

Eyal Fitoussi GEO my WordPress

CVE-2026-52715 affects Eyal Fitoussi GEO my WordPress. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-52712

tnomi Attendance Manager

CVE-2026-52712 affects tnomi Attendance Manager. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.