Search
Search Results (373402 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66699 | 2026-08-06 | 5.3 Medium | ||
| Custom role Broken Access Control in Dokan <= 5.0.10 versions. | ||||
| CVE-2026-66695 | 2026-08-06 | 6.5 Medium | ||
| Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions. | ||||
| CVE-2026-66694 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions. | ||||
| CVE-2026-66690 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions. | ||||
| CVE-2026-66664 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions. | ||||
| CVE-2026-66470 | 2026-08-06 | 7.1 High | ||
| Subscriber Broken Access Control in Frontend Admin by DynamiApps <= 3.29.10 versions. | ||||
| CVE-2026-66457 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | ||||
| CVE-2026-66440 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | ||||
| CVE-2026-65581 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. | ||||
| CVE-2026-65578 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Agora <= 1.9 versions. | ||||
| CVE-2026-65577 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions. | ||||
| CVE-2026-65576 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions. | ||||
| CVE-2026-65575 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions. | ||||
| CVE-2026-65570 | 2026-08-06 | 8.1 High | ||
| Unauthenticated Bypass Vulnerability in Login with phone number <= 1.8.70 versions. | ||||
| CVE-2026-16954 | 2026-08-06 | 6.5 Medium | ||
| The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, allowing users with the Editor role to read the site's stored third-party API key and authentication tokens in cleartext, despite those secrets being restricted to administrators everywhere else. | ||||
| CVE-2026-65565 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | ||||
| CVE-2026-65560 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | ||||
| CVE-2026-65559 | 2026-08-06 | 7.2 High | ||
| Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | ||||
| CVE-2026-65552 | 2026-08-06 | 9.8 Critical | ||
| Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions. | ||||
| CVE-2026-65549 | 2026-08-06 | 7.2 High | ||
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | ||||