Search Results (29936 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-39519 2 Ahmad, Wordpress 2 Geekybot, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
CVE-2026-39530 2 Speakout!, Wordpress 2 Speakout! Email Petitions, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
CVE-2026-39591 2 Cmsjunkie – Wordpress Business Directory Plugins, Wordpress 2 Wp-businessdirectory, Wordpress 2026-06-23 9.9 Critical
Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
CVE-2026-40771 2 Wasiliy Strecker, Wordpress 2 Contest Gallery, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
CVE-2026-40772 2 Ahmad, Wordpress 2 Geekybot, Wordpress 2026-06-23 10 Critical
Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
CVE-2026-42381 2 Funnelkit, Wordpress 2 Funnel Builder By Funnelkit, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
CVE-2026-42665 2 Passionate Programmer Peter, Wordpress 2 Wp Data Access, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
CVE-2026-45439 2 Realtyna, Wordpress 2 Realtyna Organic Idx Plugin, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
CVE-2026-48836 2 Mantrabrain, Wordpress 2 Easy Invoice, Wordpress 2026-06-23 10 Critical
Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
CVE-2026-48886 2 Ahmad, Wordpress 2 Js Help Desk, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
CVE-2026-49067 2 Wordpress, Yydevelopment 2 Wordpress, Advanced 301 And 302 Redirect 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
CVE-2026-12087 1 Pevans 1 Socket 2026-06-23 9.1 Critical
Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer. Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.
CVE-2026-11832 1 Biafra 1 Dancer2::plugin::auth::oauth 2026-06-23 9.1 Critical
Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.
CVE-2026-39574 2 Realmag777, Wordpress 2 Inpost Gallery, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.
CVE-2026-52715 2 Eyal Fitoussi, Wordpress 2 Geo My Wordpress, Wordpress 2026-06-23 9.3 Critical
Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.
CVE-2026-49774 2 Filipe Nasc, Wordpress 2 Rd Station, Wordpress 2026-06-23 9.9 Critical
Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
CVE-2026-40750 2 Themagnifico52, Wordpress 2 Kids Online Store, Wordpress 2026-06-23 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.
CVE-2025-69108 2 Themerex, Wordpress 2 Hot Coffee, Wordpress 2026-06-23 9.8 Critical
Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.
CVE-2025-69122 2 Themerex, Wordpress 2 Seafood Company, Wordpress 2026-06-23 9.8 Critical
Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
CVE-2026-27429 2 Boldthemes, Wordpress 2 Nifty, Wordpress 2026-06-23 9.8 Critical
Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.