Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-65309
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way passw…
No fix yet
MEDIUM 5.4
CVE-2026-18211
A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security…
Build Of Keycloak
No fix yet
HIGH 8.1
CVE-2026-18215
Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove…
Build Of Keycloak
No fix yet
HIGH 8.1
CVE-2026-18214
Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-18208
A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme…
Build Of Keycloak
No fix yet
MEDIUM 6.5
CVE-2026-18203
A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p…
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-8155
The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated …
No fix yet
CRITICAL 10.0
CVE-2026-18452
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed AP…
No fix yet
HIGH 8.8
CVE-2026-16236
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing …
Mitigation only
HIGH 8.1
CVE-2026-15258
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before…
No fix yet
MEDIUM 6.5
CVE-2026-15209
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated…
No fix yet
HIGH 7.5
CVE-2026-15048
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to re…
No fix yet
MEDIUM 6.5
CVE-2026-14931
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capabi…
No fix yet
HIGH 7.5
CVE-2026-14930
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allo…
No fix yet
MEDIUM 6.5
CVE-2026-14928
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce…
No fix yet
MEDIUM 6.1
CVE-2026-14922
WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (do…
No fix yet
MEDIUM 6.1
CVE-2026-14921
The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(),
No fix yet
CRITICAL 9.8
CVE-2026-14919
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check t…
No fix yet
MEDIUM 6.1
CVE-2026-14845
The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and …
No fix yet
MEDIUM 5.3
CVE-2026-14843
The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an un…
No fix yet
MEDIUM 6.5
CVE-2026-14834
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers …
No fix yet
MEDIUM 6.8
CVE-2026-14833
The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image light…
No fix yet
HIGH 7.5
CVE-2026-14830
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the asso…
No fix yet
MEDIUM 6.5
CVE-2026-14554
The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing use…
No fix yet
CRITICAL 9.8
CVE-2026-14483
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5…
Mitigation only
HIGH 7.5
CVE-2026-14333
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and witho…
No fix yet
HIGH 7.5
CVE-2026-14319
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing…
No fix yet
MEDIUM 5.3
CVE-2026-14317
The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it…
No fix yet
HIGH 8.8
CVE-2026-13609
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which rest…
Mitigation only
HIGH 7.2
CVE-2026-13392
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative cap…
No fix yet