NVD Vulnerabilities

Severity Distribution

Publication Trend

Vulnerability Database

CVE ID Description Published Base Score Attack Vector Severity Actions
CVE-2026-15245 The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript context before echoing it into an... 2026-08-07 5.4 NETWORK MEDIUM NVD
CVE-2026-15215 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing and activating a Subscriptions... 2026-08-07 8.8 NETWORK HIGH NVD
CVE-2026-15214 The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription being viewed before rendering... 2026-08-07 4.3 NETWORK MEDIUM NVD
CVE-2026-15032 The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an HTML attribute, allowing unau... 2026-08-07 6.1 NETWORK MEDIUM NVD
CVE-2026-14943 The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API acce... 2026-08-07 7.5 NETWORK HIGH NVD
CVE-2026-14331 The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a public subscription form, lea... 2026-08-07 6.1 NETWORK MEDIUM NVD
CVE-2026-14205 The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price ... 2026-08-07 9.8 NETWORK CRITICAL NVD
CVE-2026-49005 The root password hash of the device can be obtained through unencrypted information in the firmware. 2026-08-07 2.4 PHYSICAL LOW NVD
CVE-2026-49746 Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases ... 2026-08-07 7.1 LOCAL HIGH NVD
CVE-2026-45204 Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference in... 2026-08-07 5.5 LOCAL MEDIUM NVD
CVE-2026-45198 Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using d... 2026-08-07 7.8 LOCAL HIGH NVD
CVE-2026-70332 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to... 2026-08-07 9.6 NETWORK CRITICAL NVD
CVE-2026-68823 Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network. 2026-08-07 9.1 NETWORK CRITICAL NVD
CVE-2026-65668 Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. 2026-08-07 8.8 NETWORK HIGH NVD
CVE-2026-65667 Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network. 2026-08-07 10.0 NETWORK CRITICAL NVD