Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2026-14207
The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, a…
No fix yet
HIGH 8.6
CVE-2026-13395
The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from …
No fix yet
MEDIUM 5.3
CVE-2026-13345
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCom…
No fix yet
MEDIUM 6.1
CVE-2026-13330
The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upl…
No fix yet
HIGH 7.5
CVE-2026-13178
The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauth…
No fix yet
MEDIUM 5.3
CVE-2026-13143
The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before mark…
No fix yet
HIGH 7.5
CVE-2026-12687
The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registrat…
No fix yet
HIGH 7.5
CVE-2026-12500
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress …
No fix yet
MEDIUM 6.1
CVE-2026-11881
The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside…
No fix yet
MEDIUM 5.4
CVE-2026-11870
The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting…
No fix yet
MEDIUM 6.5
CVE-2026-11867
The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and d…
No fix yet
MEDIUM 5.9
CVE-2026-11782
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update actio…
No fix yet
HIGH 7.5
CVE-2026-1360
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th…
No fix yet
CRITICAL 9.8
CVE-2026-16610
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via…
No fix yet
HIGH 8.8
CVE-2026-14356
The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin …
Mitigation only
MEDIUM 5.3
CVE-2026-1982
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is d…
No fix yet
MEDIUM 6.5
CVE-2026-16092
The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action…
No fix yet
HIGH 7.3
CVE-2026-16727
Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbi…
No fix yet
HIGH 7.1
CVE-2026-15929
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection.…
No fix yet
CRITICAL 9.6
CVE-2026-17713
Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had comp…
No fix yet
CRITICAL 9.6
CVE-2026-17701
Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the …
No fix yet
MEDIUM 5.1
CVE-2026-62946
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, proc…
No fix yet
HIGH 7.3
CVE-2025-69949
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
No fix yet
HIGH 7.3
CVE-2025-69945
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
No fix yet
HIGH 7.3
CVE-2025-69944
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.
No fix yet
CRITICAL 9.8
CVE-2025-69943
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
Mitigation only
CRITICAL 9.8
CVE-2025-69942
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
No fix yet
HIGH 7.3
CVE-2025-67408
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
No fix yet
HIGH 7.3
CVE-2025-67407
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
No fix yet
HIGH 7.3
CVE-2025-67406
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). T…
No fix yet