Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-15338
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via th…
No fix yet
MEDIUM 6.5
CVE-2026-15073
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al…
Mitigation only
MEDIUM 6.5
CVE-2026-15072
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al…
Mitigation only
HIGH 8.8
CVE-2026-13353
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all vers…
No fix yet
MEDIUM 6.5
CVE-2026-13262
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val'…
Mitigation only
HIGH 7.2
CVE-2026-13114
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and Us…
Mitigation only
MEDIUM 5.3
CVE-2026-12426
The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in…
Mitigation only
HIGH 8.8
CVE-2026-13756
The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing au…
Mitigation only
MEDIUM 6.5
CVE-2026-11426
The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to th…
Mitigation only
HIGH 7.5
CVE-2026-44383
Multiple connections to the backend using the same charging station ID
are allowed, which could allow an attacker to deploy multiple instances
of m…
Mitigation only
HIGH 7.5
CVE-2026-42952
Previously, there was no throttling on repeated authentication attempts
to the charging station backend, which could allow an attacker to
execute a…
Mitigation only
CRITICAL 9.1
CVE-2026-15089
vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.
No fix yet
MEDIUM 5.9
CVE-2026-15087
vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.
No fix yet
MEDIUM 5.9
CVE-2026-15086
vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.
No fix yet
CRITICAL 9.8
CVE-2026-20744
The charging station websocket endpoint accepts connections without
proper authentication, which could lead to privilege escalation.
Mitigation only
CRITICAL 9.9
CVE-2026-14480
OpenPLC Runtime v3 contains an authenticated arbitrary file write
vulnerability in the legacy web UI program‑upload workflow. The
application store…
Mitigation only
MEDIUM 5.9
CVE-2026-11915
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
No fix yet
MEDIUM 5.9
CVE-2026-11914
vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.
No fix yet
CRITICAL 9.8
CVE-2026-11913
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
No fix yet
MEDIUM 5.3
CVE-2026-47422
Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and t…
Mitigation only
CRITICAL 9.8
CVE-2026-57807
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Cli…
Mitigation only
HIGH 7.1
CVE-2026-55880
OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the owners…
Mitigation only
MEDIUM 5.3
CVE-2026-13039
The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a …
Mitigation only
CRITICAL 9.8
CVE-2026-12761
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to …
Mitigation only
MEDIUM 6.4
CVE-2026-11321
The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, wi…
Mitigation only
HIGH 8.8
CVE-2026-6212
Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse.
This issue aff…
Mitigation only
CRITICAL 9.8
CVE-2026-5801
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt…
Mitigation only
MEDIUM 5.9
CVE-2026-15146
GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP se…
Mitigation only
CRITICAL 9.8
CVE-2026-2397
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows…
Mitigation only
MEDIUM 6.8
CVE-2026-55885
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the …
Mitigation only