Search

Search Results (374284 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66439 2 Berocket, Wordpress 2 Advanced Ajax Product Filters, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-19061 1 Insta 1 Instaknxserviceapp 2026-08-06 3.7 Low
A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitation is known to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-65545 2 Jordy Meow, Wordpress 2 Ai-engine, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-65560 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
CVE-2026-65577 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-66457 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
CVE-2026-18427 2026-08-06 7.5 High
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route based guard using a non canonical path form that misses the guarded route yet resolves back onto the protected file, disclosing its contents. Applications that protect a subtree of the static root with a route based guard are affected, while applications relying on the allowedPath option are not. This is fixed in @fastify/static 10.1.3, which canonicalizes the pathname, including rejecting backslashes, on the path used for routing and serving.
CVE-2026-3430 2026-08-06 8.6 High
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
CVE-2026-66678 2 Justinkruit, Wordpress 2 Advanced Custom Fields:font Awesome Field, Wordpress 2026-08-06 4.3 Medium
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
CVE-2026-66684 2 Akshaymenariya, Wordpress 2 Export Import Menus, Wordpress 2026-08-06 5.3 Medium
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-66688 2 Brainstormforce, Wordpress 2 Ultimate Addons For Elementor, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
CVE-2026-56699 1 Wazuh 1 Wazuh 2026-08-06 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.
CVE-2026-66694 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
CVE-2026-28146 2 Unlimited-elements, Wordpress 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress 2026-08-06 6.5 Medium
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
CVE-2026-66702 2 Rank Math Seo, Wordpress 2 Rank Math Seo, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-34501 1 Apache 1 Portable Runtime Utility 2026-08-06 7.5 High
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-66692 2 Colissimo, Wordpress 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress 2026-08-06 4.3 Medium
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-66695 2 Boldgrid, Wordpress 2 W3 Total Cache, Wordpress 2026-08-06 6.5 Medium
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-66703 2 Properfraction, Wordpress 2 Mailoptin, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVE-2026-6235 2 Sendmachine, Wordpress 2 Sendmachine For Wordpress, Wordpress 2026-08-06 9.8 Critical
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the plugin's SMTP configuration, which can be leveraged to intercept all outbound emails from the site (including password reset emails).