Live feed

CVE Feed

Last 30 days — 14,992 matching across all industries.

Showing 40

Auto-refreshupdated just now
CVE-2026-84849
MEDIUM· 6.5

Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.

29d ago
CVE-2026-84848
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.

29d ago
CVE-2026-84847
HIGH· 7.5

Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

29d ago
CVE-2026-84836
HIGH· 7.1

Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.

29d ago
CVE-2026-84834
CRITICAL· 9.8

Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

29d ago
CVE-2026-84814
CRITICAL· 9.8

Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

29d ago
CVE-2026-84813
CRITICAL· 9.3

Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

29d ago
CVE-2026-84812
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

29d ago
CVE-2026-84779
HIGH· 8.1

Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt &amp; MCP for AI Agents <= 1.51.0 versions.

29d ago
CVE-2026-84778
HIGH· 7.5

Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration &amp; Cloning <= 6.65 versions.

29d ago
CVE-2026-84777
HIGH· 7.4

Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.

29d ago
CVE-2026-84776
HIGH· 7.5

Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.

29d ago
CVE-2026-84774
MEDIUM· 6.1

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.

29d ago
CVE-2026-84773
HIGH· 7.2

Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.

29d ago
CVE-2026-84769
MEDIUM· 6.5

Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.

29d ago
CVE-2026-84768
CRITICAL· 9.3

Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

29d ago
CVE-2026-84767
MEDIUM· 5.3

Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.

29d ago
CVE-2026-84766
MEDIUM· 5.9

Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.

29d ago
CVE-2026-84765
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.

29d ago
CVE-2026-84763
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.

29d ago
CVE-2026-84762
MEDIUM· 5.3

Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.

29d ago
CVE-2026-84761
HIGH· 7.2

Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.

29d ago
CVE-2026-84758
MEDIUM· 6.5

Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.

29d ago
CVE-2026-84757
HIGH· 8.2

Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.

29d ago
CVE-2026-84756
HIGH· 7.1

Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.

29d ago
CVE-2026-84755
MEDIUM· 6.5

Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.

29d ago
CVE-2026-84754
MEDIUM· 6.5

Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.

29d ago
CVE-2026-84753
CRITICAL· 9.8

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

29d ago
CVE-2026-84752
HIGH· 8.8

Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

29d ago
CVE-2026-84736
NONE

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification. As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens. The issue has been addressed by enabling TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment.

29d ago
CVE-2026-84238
CRITICAL· 9.8

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

29d ago
CVE-2026-84215
MEDIUM· 6.5

Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

29d ago
CVE-2026-81776
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

29d ago
CVE-2026-81773
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

29d ago
CVE-2026-81300
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

29d ago
CVE-2026-81295
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

29d ago
CVE-2026-81292
HIGH· 7.1

Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

29d ago
CVE-2026-81282
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

29d ago
CVE-2026-81281
MEDIUM· 6.5

Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

29d ago
CVE-2026-75602
MEDIUM· 6.5

OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before transferring them to the user's destination storage. The temporary filename comes from the attacker-controlled Content-Disposition header, is passed from parseFilenameFromContentDisposition in internal/offline_download/http/util.go to filepath.Join(task.TempDir, filename) in SimpleHttp.Run in internal/offline_download/http/client.go, and is opened with os.Create without a containment check. Because filepath.Join cleans .. segments, a non-admin user with PermAddOfflineDownload on any path can traverse out of task.TempDir and create, truncate, or overwrite any file writable by the OpenList process whose parent directory already exists. The server/handles/offline_download.go AddOfflineDownload route uses normal user authentication rather than AuthAdmin, and local-storage destinations fall through tryPutUrl in internal/offline_download/tool/add.go to the vulnerable SimpleHttp.Run path. This issue is fixed in version 4.2.3.

29d ago
Feedback

How was this page?

Spotted something off, or have an idea? Let us know.

0/1000