Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2026-18570
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin…
Build Of Keycloak
No fix yet
MEDIUM 5.4
CVE-2026-16292
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing…
No fix yet
HIGH 7.5
CVE-2026-16540
The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own rec…
No fix yet
HIGH 7.5
CVE-2026-16285
The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a…
No fix yet
CRITICAL 9.8
CVE-2026-16256
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us…
No fix yet
HIGH 7.5
CVE-2026-16261
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it iss…
No fix yet
MEDIUM 6.6
CVE-2026-16062
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its…
No fix yet
MEDIUM 5.4
CVE-2026-16064
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when qui…
No fix yet
MEDIUM 5.4
CVE-2026-16063
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with p…
No fix yet
MEDIUM 5.5
CVE-2026-15248
The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing …
No fix yet
MEDIUM 5.4
CVE-2026-15385
The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-men…
No fix yet
HIGH 7.5
CVE-2026-15241
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing …
No fix yet
HIGH 7.5
CVE-2026-15236
The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the con…
No fix yet
HIGH 7.5
CVE-2026-15206
The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after a…
No fix yet
HIGH 7.5
CVE-2026-15151
The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users …
No fix yet
HIGH 8.2
CVE-2026-14920
## Summary
No fix yet
MEDIUM 5.4
CVE-2026-14864
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users wit…
No fix yet
MEDIUM 6.1
CVE-2026-14841
The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribu…
No fix yet
MEDIUM 6.8
CVE-2026-14817
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a…
No fix yet
HIGH 8.1
CVE-2026-12586
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CS…
No fix yet
MEDIUM 6.5
CVE-2026-13389
The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthen…
No fix yet
MEDIUM 6.5
CVE-2026-9335
A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalL…
Patch available
CRITICAL 9.8
CVE-2026-8457
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to …
No fix yet
HIGH 7.5
CVE-2026-18352
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' p…
No fix yet
HIGH 7.5
CVE-2026-13339
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_c…
No fix yet
HIGH 7.4
CVE-2026-18556 KEV
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-centra…
N Central
after 2026.1
HIGH 7.5
CVE-2026-55735
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged …
Guardian
2.4.1+
HIGH 7.5
CVE-2026-55734
Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via…
Guardian
2.4.1+
HIGH 7.5
CVE-2026-55733
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-control…
Guardian
2.4.1+
HIGH 7.5
CVE-2026-54894
Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influen…
Guardian
2.4.1+