Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2026-15464
The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to,…
No fix yet
MEDIUM 6.4
CVE-2026-15334
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…
No fix yet
MEDIUM 6.4
CVE-2026-15333
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…
No fix yet
MEDIUM 5.3
CVE-2026-12654
The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. Th…
No fix yet
HIGH 7.5
CVE-2026-14603
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated us…
No fix yet
HIGH 7.8
CVE-2026-14172
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, al…
No fix yet
HIGH 7.5
CVE-2026-12981
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthentica…
No fix yet
CRITICAL 9.1
CVE-2026-12877
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it…
No fix yet
MEDIUM 5.4
CVE-2026-12689
The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions,…
No fix yet
MEDIUM 6.5
CVE-2026-12688
The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthentic…
No fix yet
HIGH 7.5
CVE-2026-12497
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not …
No fix yet
HIGH 8.8
CVE-2026-16870
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati…
No fix yet
HIGH 7.2
CVE-2026-66138
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic…
No fix yet
MEDIUM 5.5
CVE-2026-54422
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the cre…
No fix yet
MEDIUM 6.4
CVE-2026-6454
The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to i…
No fix yet
MEDIUM 6.4
CVE-2026-15100
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all …
No fix yet
MEDIUM 5.3
CVE-2026-13464
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…
No fix yet
HIGH 8.0
CVE-2026-12736
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::sa…
No fix yet
MEDIUM 5.3
CVE-2026-11354
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the …
No fix yet
MEDIUM 6.4
CVE-2025-9205
The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficien…
No fix yet
CRITICAL 9.8
CVE-2026-62825
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Azure Key Vault
No fix yet
CRITICAL 9.8
CVE-2026-58275
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Azure Dns
No fix yet
CRITICAL 10.0
CVE-2026-56191
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Exchange Online
No fix yet
HIGH 8.8
CVE-2026-56167
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
Azure Ai Search
No fix yet
CRITICAL 9.8
CVE-2026-56165
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
Account
No fix yet
CRITICAL 9.9
CVE-2026-56160
Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.
Azure Red Hat Openshift
No fix yet
HIGH 8.8
CVE-2026-54120
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Surface Management Services
No fix yet
CRITICAL 9.9
CVE-2026-50517
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
365 Copilot
No fix yet
MEDIUM 6.5
CVE-2026-49159
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Graph
No fix yet
HIGH 7.2
CVE-2026-35425
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Azure Api Management
No fix yet