NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-4379 The LightPress Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `group` attribute in the `[gallery]` shortcode in al... 2026-04-08 6.4 NETWORK MEDIUM NVD
CVE-2026-2988 The Blubrry PowerPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'powerpress' and 'podcast' shortcodes in versions up ... 2026-04-08 6.4 NETWORK MEDIUM NVD
CVE-2026-5726 ASDA-Soft Stack-based Buffer Overflow Vulnerability 2026-04-08 7.8 LOCAL HIGH NVD
CVE-2026-1163 An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails to invalidate active sessions ... 2026-04-08 N/A None None NVD
CVE-2026-3499 The Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in v... 2026-04-08 8.8 NETWORK HIGH NVD
CVE-2026-3296 The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrus... 2026-04-08 9.8 NETWORK CRITICAL NVD
CVE-2026-33810 When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a d... 2026-04-08 7.5 NETWORK HIGH NVD
CVE-2026-32289 Context was not properly tracked across template branches for JS template literals, leading to possibly incorrect escaping of content when branches we... 2026-04-08 6.1 NETWORK MEDIUM NVD
CVE-2026-32288 tar.Reader can allocate an unbounded amount of memory when reading a maliciously-crafted archive containing a large number of sparse regions encoded i... 2026-04-08 5.5 LOCAL MEDIUM NVD
CVE-2026-32283 If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrol... 2026-04-08 7.5 NETWORK HIGH NVD
CVE-2026-32282 On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the syml... 2026-04-08 6.4 LOCAL MEDIUM NVD
CVE-2026-32281 Validating certificate chains which use policies is unexpectedly inefficient when certificates in the chain contain a very large number of policy mapp... 2026-04-08 7.5 NETWORK HIGH NVD
CVE-2026-32280 During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyO... 2026-04-08 7.5 NETWORK HIGH NVD
CVE-2026-27144 The compiler is meant to unwrap pointers which are the operands of a memory move; a no-op interface conversion prevented the compiler from making the ... 2026-04-08 7.1 LOCAL HIGH NVD
CVE-2026-27143 Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid i... 2026-04-08 9.8 NETWORK CRITICAL NVD