Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2026-13110
The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a mis…
No fix yet
CRITICAL 10.0
CVE-2026-65880
Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code exec…
No fix yet
MEDIUM 5.1
CVE-2026-63303
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash…
No fix yet
MEDIUM 5.1
CVE-2026-63302
Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges …
No fix yet
HIGH 7.0
CVE-2026-63301
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; h…
No fix yet
MEDIUM 6.3
CVE-2026-18029
Our payment integration with GiroCheckout did not properly validate
payment status responses. An attacker could use a successful payment
status res…
No fix yet
MEDIUM 6.9
CVE-2026-65624
Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connectio…
Patch available
HIGH 8.7
CVE-2026-59248
Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on …
Patch available
CRITICAL 9.8
CVE-2026-16462
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL comm…
No fix yet
HIGH 7.5
CVE-2026-14785
The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1…
No fix yet
HIGH 8.8
CVE-2026-14328
The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all version…
No fix yet
CRITICAL 9.4
CVE-2026-11841
An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to imprope…
Mitigation only
MEDIUM 5.0
CVE-2026-11598
The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including…
No fix yet
HIGH 7.5
CVE-2026-10207
The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficie…
No fix yet
MEDIUM 5.8
CVE-2026-9680
Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to …
No fix yet
MEDIUM 6.1
CVE-2026-8167
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Re…
No fix yet
HIGH 7.2
CVE-2026-61376
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exp…
No fix yet
HIGH 7.2
CVE-2026-59764
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an …
No fix yet
MEDIUM 5.2
CVE-2026-44387
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is explo…
No fix yet
MEDIUM 6.5
CVE-2026-15267
The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_…
No fix yet
HIGH 7.5
CVE-2026-14516
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' para…
No fix yet
MEDIUM 6.1
CVE-2026-14171
An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website.…
No fix yet
HIGH 8.1
CVE-2026-14169
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing u…
No fix yet
HIGH 8.8
CVE-2026-14168
A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulti…
Mitigation only
HIGH 8.8
CVE-2026-14167
A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level including permission management du…
No fix yet
HIGH 7.5
CVE-2026-13161
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection via the 'alldata[truebooker_use…
No fix yet
HIGH 7.5
CVE-2026-12800
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-js…
No fix yet
MEDIUM 6.4
CVE-2026-15730
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Si…
No fix yet
CRITICAL 9.8
CVE-2026-15014
The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass …
No fix yet
HIGH 7.5
CVE-2026-12741
The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter i…
No fix yet