Data sources·vuln
NVD CVE 2.0
nvd
Runs in 30d
0
0 ok · 0 err
Success rate
—
last 30 days
Inserted (30d)
0
new rows
Updated (30d)
0
re-merged rows
Recent runs
| Started | Status | Inserted | Updated | Error / cursor |
|---|---|---|---|---|
| No runs in the last 30 days. | ||||
Recent vulnerabilities from this source
- CVE-2026-5513High· 7.2The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sani33 m ago
- CVE-2026-49818——2 h ago
- CVE-2026-46373——2 h ago
- CVE-2026-46374——2 h ago
- CVE-2026-1291Medium· 4.3The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all versions up to, and including, 5.4.4 This mak2 h ago
- CVE-2026-11624—The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. I2 h ago
- CVE-2026-53441—Jenkins: Stored XSS vulnerability in node offline cause description 3 h ago
- CVE-2026-9629Medium· 6.4The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenti4 h ago
- CVE-2026-3297Medium· 6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Anchor block in versions up to, and including, 2.0.9 due to insufficient input sanitization and output esc4 h ago
- CVE-2026-2470Medium· 4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.9. This is due to the pagelayer_save_content AJAX handler allowing users wit4 h ago
- CVE-2026-9134Medium· 6.4The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31 This is due to an incomplete JavaScript event handler blacklist in 5 h ago
- CVE-2026-9109High· 7.2The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Translation Storage in all versions up to, and including, 2.31 due 5 h ago
- CVE-2026-9062—The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing high-privileged users such as administrators to read arbitrary `.php` files from the server, including configuration file5 h ago
- CVE-2026-9061—The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and outputting it on the Store Locator WordPress plugin before 1.6.9 admin page, allowing high-privileged users such as admin5 h ago
- CVE-2026-11769—We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports l6 h ago