Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.3
CVE-2026-18367
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 a…
No fix yet
CRITICAL 9.8
CVE-2026-17032
Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attacker…
No fix yet
HIGH 7.5
CVE-2026-16620
The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Se…
No fix yet
HIGH 7.5
CVE-2026-16619
The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a …
No fix yet
CRITICAL 9.8
CVE-2026-15734
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary c…
No fix yet
CRITICAL 9.8
CVE-2026-15733EPSS 14%
A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attack…
No fix yet
CRITICAL 9.8
CVE-2026-15732
A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated att…
No fix yet
MEDIUM 5.3
CVE-2026-16067
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non…
No fix yet
MEDIUM 5.3
CVE-2026-15208
The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against th…
No fix yet
MEDIUM 5.3
CVE-2026-15152
The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own mercha…
No fix yet
MEDIUM 5.3
CVE-2026-15149
The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a…
No fix yet
MEDIUM 5.3
CVE-2026-15147
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to v…
No fix yet
MEDIUM 5.3
CVE-2026-14936
The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant…
No fix yet
MEDIUM 5.3
CVE-2026-14842
The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauth…
No fix yet
MEDIUM 5.3
CVE-2026-14831
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when a…
No fix yet
CRITICAL 10.0
CVE-2026-14812
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, …
No fix yet
HIGH 7.5
CVE-2026-13399
The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau…
No fix yet
MEDIUM 5.3
CVE-2026-13342
The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, …
No fix yet
MEDIUM 5.9
CVE-2026-12901
The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated atta…
No fix yet
HIGH 7.5
CVE-2026-12584
The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notific…
No fix yet
MEDIUM 5.3
CVE-2026-12501
The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured mer…
No fix yet
CRITICAL 10.0
CVE-2026-11976
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) …
No fix yet
HIGH 7.8
CVE-2026-11803
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage thi…
No fix yet
MEDIUM 5.9
CVE-2026-11361
The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete…
No fix yet
HIGH 7.5
CVE-2026-10599
The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order bein…
No fix yet
HIGH 7.5
CVE-2026-10524
The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the c…
No fix yet
CRITICAL 9.0
CVE-2025-14561
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing suffici…
No fix yet
MEDIUM 5.0
CVE-2025-12317
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens assoc…
No fix yet
HIGH 8.8
CVE-2024-39024
In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.
No fix yet
MEDIUM 6.8
CVE-2024-6541
The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows aut…
No fix yet