Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-18946
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a pub…
No fix yet
HIGH 7.5
CVE-2026-18470
The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not …
No fix yet
HIGH 8.1
CVE-2026-18030
The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one…
No fix yet
HIGH 8.8
CVE-2026-17540
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a s…
No fix yet
MEDIUM 5.3
CVE-2026-17021
The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does…
No fix yet
HIGH 7.5
CVE-2026-17542
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any aut…
No fix yet
HIGH 7.5
CVE-2026-17541
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to re…
No fix yet
HIGH 7.5
CVE-2026-17022
The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wi…
No fix yet
MEDIUM 5.3
CVE-2026-17012
The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a…
No fix yet
HIGH 8.8
CVE-2026-16985
The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-…
No fix yet
MEDIUM 5.8
CVE-2026-16949
The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthent…
No fix yet
CRITICAL 9.8
CVE-2026-16299
The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to r…
No fix yet
CRITICAL 9.8
CVE-2026-16298
The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset th…
No fix yet
MEDIUM 6.1
CVE-2026-17019
The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict…
No fix yet
MEDIUM 5.4
CVE-2026-17010
The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing user…
No fix yet
MEDIUM 5.3
CVE-2026-15229
The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated user…
No fix yet
HIGH 8.2
CVE-2026-16257
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can b…
No fix yet
MEDIUM 5.4
CVE-2026-15238
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticat…
No fix yet
MEDIUM 5.3
CVE-2026-15237
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payme…
No fix yet
MEDIUM 6.8
CVE-2026-15047
The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, all…
No fix yet
MEDIUM 5.4
CVE-2026-14941
The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX act…
No fix yet
MEDIUM 5.3
CVE-2026-14860
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing…
No fix yet
HIGH 8.8
CVE-2026-14293
The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and do…
No fix yet
HIGH 7.2
CVE-2026-13170
The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing user…
No fix yet
HIGH 7.2
CVE-2026-14237
The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-s…
No fix yet
HIGH 8.1
CVE-2026-13600
The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator a…
No fix yet
HIGH 7.5
CVE-2026-14206
The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing…
No fix yet
HIGH 8.4
CVE-2026-13133
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path with…
No fix yet
MEDIUM 5.5
CVE-2026-12570
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the …
Patch available
MEDIUM 6.2
CVE-2026-72522
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Uni…
Patch available