Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-32469
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
No fix yet
MEDIUM 5.3
CVE-2026-28180
Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.
No fix yet
MEDIUM 5.9
CVE-2026-28179
Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-28178
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
No fix yet
HIGH 7.1
CVE-2026-28177
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
No fix yet
HIGH 7.1
CVE-2026-28172
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
No fix yet
MEDIUM 5.3
CVE-2026-28169
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-28146
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
No fix yet
HIGH 7.1
CVE-2026-28143
Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
No fix yet
HIGH 7.1
CVE-2026-28141
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
No fix yet
HIGH 7.5
CVE-2026-28140
Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28139
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
No fix yet
HIGH 8.8
CVE-2026-28111
Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
No fix yet
HIGH 7.1
CVE-2026-28082
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
No fix yet
CRITICAL 9.8
CVE-2026-28005
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
No fix yet
MEDIUM 6.5
CVE-2026-25403
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
No fix yet
MEDIUM 5.3
CVE-2026-19045
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file…
No fix yet
MEDIUM 5.3
CVE-2026-19044
A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the…
No fix yet
CRITICAL 9.8
CVE-2026-5134
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C…
No fix yet
HIGH 8.3
CVE-2026-16731
OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may …
No fix yet
HIGH 8.7
CVE-2026-16315
OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may …
No fix yet
HIGH 7.5
CVE-2026-65551
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects…
No fix yet
MEDIUM 5.3
CVE-2026-19039
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of t…
No fix yet
HIGH 7.2
CVE-2026-19036
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulatio…
No fix yet
MEDIUM 5.3
CVE-2026-0673
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via t…
No fix yet
MEDIUM 5.4
CVE-2026-8166
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pu…
No fix yet
MEDIUM 6.4
CVE-2026-5391
The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' …
No fix yet
MEDIUM 6.4
CVE-2026-5158
The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '…
No fix yet
HIGH 7.2
CVE-2026-19035
A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The m…
No fix yet
MEDIUM 5.3
CVE-2026-11983
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du…
No fix yet