Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2026-63233
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
overall an…
Mitigation only
CRITICAL 9.9
CVE-2026-63232
A SQL injection and unsafe deserialisation
vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment
reinforcem…
No fix yet
HIGH 8.1
CVE-2026-63231
A post-authentication SQL injection
vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via
the face-to-f…
No fix yet
CRITICAL 9.1
CVE-2026-63230
A pre-authentication error-based SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database
contents, …
No fix yet
CRITICAL 9.1
CVE-2026-63229
A pre-authentication blind SQL injection
vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via
the SSO …
Mitigation only
HIGH 8.1
CVE-2026-14300
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by i…
No fix yet
HIGH 7.1
CVE-2026-14234
The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker…
No fix yet
CRITICAL 9.9
CVE-2026-63227
An unrestricted SCORM file upload vulnerability
in Koollab LMS allowed
an authenticated module designer to upload a SCORM package containing a PHP
we…
No fix yet
MEDIUM 5.4
CVE-2026-14224
The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the…
No fix yet
MEDIUM 5.3
CVE-2026-13692
The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing…
No fix yet
HIGH 7.4
CVE-2026-13690
The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attac…
No fix yet
MEDIUM 6.8
CVE-2026-13605
The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into th…
No fix yet
CRITICAL 9.8
CVE-2026-13423
The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which …
No fix yet
HIGH 8.6
CVE-2026-11974
The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two A…
No fix yet
MEDIUM 5.3
CVE-2026-11351
The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenti…
No fix yet
CRITICAL 9.8
CVE-2026-18072
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a H…
No fix yet
HIGH 7.2
CVE-2026-12476
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insuffic…
No fix yet
MEDIUM 6.4
CVE-2026-17162
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' B…
No fix yet
MEDIUM 6.4
CVE-2026-17161
The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText…
No fix yet
MEDIUM 6.4
CVE-2026-15735
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up…
No fix yet
MEDIUM 6.4
CVE-2026-12939
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletter…
No fix yet
MEDIUM 6.4
CVE-2026-12938
The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode…
No fix yet
HIGH 8.8
CVE-2026-12144
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to …
No fix yet
HIGH 7.4
CVE-2026-56822
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateVali…
Netty
4.1.136 / 4.2.16+
HIGH 7.4
CVE-2026-56821
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateVali…
Netty
4.1.136 / 4.2.16+
MEDIUM 5.3
CVE-2026-66064
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened f…
Patch available
MEDIUM 6.5
CVE-2026-66063
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler s…
Patch available
CRITICAL 9.1
CVE-2026-64863
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOV…
Patch available
CRITICAL 9.1
CVE-2026-62325
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handl…
Patch available
MEDIUM 6.5
CVE-2026-59921
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constr…
Netty
4.1.136 / 4.2.16+