Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-58352
Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes …
Mitigation only
CRITICAL 9.8
CVE-2024-14037
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading …
Mitigation only
CRITICAL 9.8
CVE-2022-50973
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate…
Mitigation only
HIGH 7.8
CVE-2026-12168
An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and …
Mitigation only
HIGH 7.8
CVE-2026-12167
The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionalit…
Mitigation only
MEDIUM 5.5
CVE-2026-12166
A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via …
Mitigation only
CRITICAL 9.8
CVE-2026-4767
Missing authentication for critical function vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Authentication Abuse.
This issue affects WAF-A…
Mitigation only
CRITICAL 9.8
CVE-2026-5524
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin…
Mitigation only
MEDIUM 5.4
CVE-2026-4772
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber Defense Inc. WAF-ASP allows Stored …
Mitigation only
HIGH 8.8
CVE-2026-57766
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.
Mitigation only
HIGH 8.5
CVE-2026-57765
Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57764
Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57763
Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.
Mitigation only
MEDIUM 5.9
CVE-2026-57762
Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.
Mitigation only
HIGH 7.1
CVE-2026-57761
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
Mitigation only
MEDIUM 5.3
CVE-2026-57760
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels.
This is…
No fix yet
HIGH 8.8
CVE-2026-57759
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
Mitigation only
HIGH 7.1
CVE-2026-57758
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
Mitigation only
HIGH 7.1
CVE-2026-57757
Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
Mitigation only
HIGH 8.5
CVE-2026-57756
Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57755
Contributor Cross Site Scripting (XSS) in Mosaic Gallery – Advanced Gallery <= 1.2.0 versions.
Mitigation only
MEDIUM 6.5
CVE-2026-57754
Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.
Mitigation only
MEDIUM 5.3
CVE-2026-57753
Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
Mitigation only
HIGH 8.5
CVE-2026-57752
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
No fix yet
HIGH 8.1
CVE-2026-57751
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
Mitigation only
MEDIUM 5.3
CVE-2026-57750
Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.
Mitigation only
HIGH 7.5
CVE-2026-57749
Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
Mitigation only
HIGH 7.5
CVE-2026-57748
Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
No fix yet
MEDIUM 6.5
CVE-2026-57747
Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.
Mitigation only
HIGH 7.1
CVE-2026-57746
Subscriber Broken Access Control in Booked <= 3.0.0 versions.
Mitigation only