Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.6
CVE-2026-16062
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its…
No fix yet
MEDIUM 5.4
CVE-2026-16064
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when qui…
No fix yet
MEDIUM 5.4
CVE-2026-16063
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with p…
No fix yet
MEDIUM 5.5
CVE-2026-15248
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing …
No fix yet
MEDIUM 5.4
CVE-2026-15385
The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-men…
No fix yet
HIGH 7.5
CVE-2026-15241
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing …
No fix yet
HIGH 7.5
CVE-2026-15236
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the con…
No fix yet
HIGH 7.5
CVE-2026-15206
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after a…
No fix yet
HIGH 7.5
CVE-2026-15151
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users …
No fix yet
HIGH 8.2
CVE-2026-14920
## Summary
No fix yet
MEDIUM 5.4
CVE-2026-14864
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users wit…
No fix yet
MEDIUM 6.1
CVE-2026-14841
The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribu…
No fix yet
MEDIUM 6.8
CVE-2026-14817
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a…
No fix yet
HIGH 8.1
CVE-2026-12586
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CS…
No fix yet
MEDIUM 6.5
CVE-2026-13389
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthen…
No fix yet
CRITICAL 9.8
CVE-2026-8457
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to …
No fix yet
HIGH 7.5
CVE-2026-18352
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' p…
No fix yet
HIGH 7.5
CVE-2026-13339
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_c…
No fix yet
MEDIUM 5.9
CVE-2026-67355
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking coo…
No fix yet
MEDIUM 5.9
CVE-2026-67354
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.ref…
No fix yet
MEDIUM 5.3
CVE-2026-67353
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields w…
No fix yet
HIGH 7.6
CVE-2026-67352
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject…
No fix yet
HIGH 8.8
CVE-2026-67343
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retriev…
No fix yet
CRITICAL 9.8
CVE-2026-67342
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi…
No fix yet
CRITICAL 9.8
CVE-2026-67341
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with …
No fix yet
CRITICAL 9.8
CVE-2026-67340
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor …
Mitigation only
MEDIUM 5.3
CVE-2026-67339
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can cap…
No fix yet
MEDIUM 6.5
CVE-2026-67337
better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid …
No fix yet
HIGH 8.7
CVE-2026-67336
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and …
No fix yet
MEDIUM 5.3
CVE-2026-67335
better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without …
No fix yet