Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2026-49429
The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but …
Fix unknown
HIGH 8.4
CVE-2026-49428
Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations…
Fix unknown
HIGH 8.4
CVE-2026-49422
The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, i…
Fix unknown
HIGH 8.8
CVE-2026-49420
The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer,…
Fix unknown
HIGH 8.8
CVE-2026-19842
The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, an…
Fix unknown
MEDIUM 5.4
CVE-2026-19782
The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such a…
Fix unknown
MEDIUM 5.3
CVE-2026-19709
The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing …
Fix unknown
MEDIUM 6.5
CVE-2026-19417
The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticat…
Fix unknown
HIGH 7.1
CVE-2026-19056
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one …
Fix unknown
HIGH 7.1
CVE-2026-19055
The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes …
Fix unknown
CRITICAL 9.0
CVE-2026-18937
The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalink…
Fix unknown
MEDIUM 5.3
CVE-2026-18779
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to…
Fix unknown
MEDIUM 5.3
CVE-2026-18778
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t…
Fix unknown
MEDIUM 5.3
CVE-2026-18777
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to…
Fix unknown
CRITICAL 9.8
CVE-2026-18776
The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t…
Fix unknown
MEDIUM 5.4
CVE-2026-18466
The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with…
Fix unknown
MEDIUM 5.3
CVE-2026-18231
The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered …
Fix unknown
MEDIUM 6.8
CVE-2026-18202
The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing us…
Fix unknown
CRITICAL 10.0
CVE-2026-18051
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthentic…
Fix unknown
CRITICAL 9.8
CVE-2026-18031
The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated wi…
Fix unknown
HIGH 7.2
CVE-2026-17565
The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a serv…
Fix unknown
HIGH 8.6
CVE-2026-16950
The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing u…
Fix unknown
HIGH 8.8
CVE-2026-16617
The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public fi…
Fix unknown
HIGH 8.6
CVE-2026-16616
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, a…
Fix unknown
HIGH 7.1
CVE-2026-16570
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on on…
Fix unknown
MEDIUM 5.3
CVE-2026-16058
The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers…
Fix unknown
MEDIUM 6.8
CVE-2026-15253
The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in t…
Fix unknown
HIGH 7.5
CVE-2026-14861
The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to a…
Fix unknown
HIGH 8.8
CVE-2026-14334
The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthentica…
Fix unknown
MEDIUM 6.5
CVE-2026-13175
The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with…
Fix unknown