Search
Search Results (373321 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66690 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | ||||
| CVE-2026-66686 | 2026-08-06 | 6.5 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions. | ||||
| CVE-2026-66685 | 2026-08-06 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions. | ||||
| CVE-2026-66683 | 2026-08-06 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions. | ||||
| CVE-2026-66665 | 2026-08-06 | 10 Critical | ||
| Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions. | ||||
| CVE-2026-66664 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | ||||
| CVE-2026-66470 | 2026-08-06 | 7.1 High | ||
| Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66457 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | ||||
| CVE-2026-66452 | 2026-08-06 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. | ||||
| CVE-2026-66440 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | ||||
| CVE-2026-65581 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | ||||
| CVE-2026-65578 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | ||||
| CVE-2026-65577 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | ||||
| CVE-2026-65576 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | ||||
| CVE-2026-65575 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | ||||
| CVE-2026-65572 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions. | ||||
| CVE-2026-65571 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions. | ||||
| CVE-2026-65570 | 2026-08-06 | 8.1 High | ||
| Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. | ||||
| CVE-2026-16954 | 2026-08-06 | 6.5 Medium | ||
| The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else. | ||||
| CVE-2026-65565 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | ||||