Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-13767
The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is …
No fix yet
MEDIUM 6.4
CVE-2026-13755
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute …
No fix yet
MEDIUM 6.5
CVE-2026-13754
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, a…
No fix yet
HIGH 8.8
CVE-2026-13741
The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,…
Mitigation only
CRITICAL 9.2
CVE-2026-15925
Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacke…
No fix yet
MEDIUM 5.5
CVE-2026-12979
The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, all…
No fix yet
HIGH 7.1
CVE-2026-12978
The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its p…
No fix yet
MEDIUM 6.1
CVE-2026-12869
The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import…
No fix yet
MEDIUM 6.5
CVE-2026-12684
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media…
No fix yet
HIGH 8.1
CVE-2026-12585
The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the …
No fix yet
HIGH 8.8
CVE-2026-12525
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing …
No fix yet
MEDIUM 5.9
CVE-2026-12510
The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, al…
No fix yet
CRITICAL 9.8
CVE-2026-12492
The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authent…
No fix yet
MEDIUM 6.5
CVE-2026-12395
The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authentic…
No fix yet
MEDIUM 5.4
CVE-2026-11866
The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central…
No fix yet
MEDIUM 6.1
CVE-2026-11371
The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the featu…
No fix yet
MEDIUM 6.1
CVE-2026-15306
The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via …
No fix yet
CRITICAL 9.8
CVE-2026-15013
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version…
No fix yet
HIGH 7.2
CVE-2026-13042
The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 …
No fix yet
HIGH 7.5
CVE-2026-21729
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strat…
No fix yet
MEDIUM 6.4
CVE-2026-15652
The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Blo…
No fix yet
MEDIUM 6.4
CVE-2026-14987
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia…
No fix yet
MEDIUM 6.5
CVE-2026-12941
The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'orde…
No fix yet
HIGH 7.5
CVE-2026-12753
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' p…
No fix yet
HIGH 7.8
CVE-2026-3842
A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This o…
No fix yet
HIGH 8.1
CVE-2026-1609
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f…
Build Of Keycloak
No fix yet
MEDIUM 6.3
CVE-2026-15909
A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the fil…
No fix yet
HIGH 7.3
CVE-2026-15907
A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Exe…
No fix yet
HIGH 7.7
CVE-2026-45313
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc…
Mitigation only
HIGH 7.5
CVE-2026-36590
An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component
Nanomq
Mitigation only