NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-18367 A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 an... 2026-08-06 9.3 LOCAL CRITICAL NVD
CVE-2026-17032 Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-16620 The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Sel... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-16619 The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a c... 2026-08-06 7.5 NETWORK HIGH NVD
CVE-2026-16067 The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-15734 A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary co... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-15733 A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attacke... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-15732 A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated atta... 2026-08-06 9.8 NETWORK CRITICAL NVD
CVE-2026-15256 The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, ... 2026-08-06 4.8 NETWORK MEDIUM NVD
CVE-2026-15208 The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-15152 The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchan... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-15149 The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a ... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-15147 The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to va... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-14936 The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant ... 2026-08-06 5.3 NETWORK MEDIUM NVD
CVE-2026-14842 The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthe... 2026-08-06 5.3 NETWORK MEDIUM NVD