Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.6
CVE-2026-16950
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing u…
No fix yet
HIGH 8.8
CVE-2026-16617
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public fi…
No fix yet
HIGH 8.6
CVE-2026-16616
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, a…
No fix yet
HIGH 7.1
CVE-2026-16570
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on on…
No fix yet
MEDIUM 5.3
CVE-2026-16058
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers…
No fix yet
MEDIUM 6.8
CVE-2026-15253
The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in t…
No fix yet
HIGH 7.5
CVE-2026-14861
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to a…
No fix yet
HIGH 8.8
CVE-2026-14334
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthentica…
No fix yet
MEDIUM 6.5
CVE-2026-13175
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with…
No fix yet
HIGH 7.2
CVE-2026-13174
The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-le…
No fix yet
HIGH 8.1
CVE-2026-13169
The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned …
No fix yet
HIGH 8.6
CVE-2026-12983
The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to p…
No fix yet
HIGH 8.5
CVE-2026-11565
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing…
No fix yet
HIGH 8.8
CVE-2026-70408
An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.
No fix yet
MEDIUM 6.1
CVE-2026-66358
A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.
No fix yet
HIGH 8.1
CVE-2026-19942
The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary fil…
No fix yet
HIGH 7.3
CVE-2026-76050
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?acti…
No fix yet
HIGH 7.3
CVE-2026-76049
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php…
No fix yet
HIGH 7.3
CVE-2026-76048
A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.p…
No fix yet
CRITICAL 10.0
CVE-2026-76008
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P…
No fix yet
CRITICAL 9.9
CVE-2026-76004
A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of th…
No fix yet
CRITICAL 9.9
CVE-2026-76003
A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing…
No fix yet
HIGH 7.3
CVE-2026-75987
A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/sc…
No fix yet
HIGH 7.3
CVE-2026-75986
A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of…
No fix yet
HIGH 7.4
CVE-2026-75985
A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/ping.cgi. This manipulation of t…
No fix yet
MEDIUM 6.4
CVE-2026-15421
The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attr…
No fix yet
CRITICAL 9.1
CVE-2026-11751
A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allow…
No fix yet
HIGH 7.4
CVE-2026-75984
A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of th…
No fix yet
MEDIUM 6.3
CVE-2026-75979
A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerCo…
No fix yet
MEDIUM 6.3
CVE-2026-75978
A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController…
No fix yet