Search

Search Results (374095 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-3430 2026-08-06 8.6 High
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
CVE-2026-18277 2026-08-06 7.1 High
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path
CVE-2026-66678 2 Justinkruit, Wordpress 2 Advanced Custom Fields:font Awesome Field, Wordpress 2026-08-06 4.3 Medium
Contributor Broken Access Control in Advanced Custom Fields: Font Awesome Field <= 6.1.1 versions.
CVE-2026-66684 2 Akshaymenariya, Wordpress 2 Export Import Menus, Wordpress 2026-08-06 5.3 Medium
Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.
CVE-2026-66688 2 Brainstormforce, Wordpress 2 Ultimate Addons For Elementor, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.
CVE-2026-66685 2026-08-06 5.3 Medium
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
CVE-2026-56699 1 Wazuh 1 Wazuh 2026-08-06 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy, vulnerabilities affecting only non-GA versions are not eligible for a CVE ID.
CVE-2026-66694 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
CVE-2026-11976 2026-08-06 10 Critical
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct variants were observed on 2026-06-11, all sharing the same AES-256-GCM key, confirming a single threat actor. The attacker retains write access to the S3 bucket and has been actively iterating on the payload throughout the day.
CVE-2026-71327 2026-08-06 N/A
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
CVE-2026-5336 2026-08-06 6.8 Medium
The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users who view the affected content.
CVE-2026-71326 2026-08-06 N/A
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the delimiter-free concatenation of password and secret, allowing an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. This issue is fixed in 3.6.25 and 3.7.10.
CVE-2026-19059 1 Foundationagents 1 Metagpt 2026-08-06 3.3 Low
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-64993 2026-08-06 6.8 Medium
Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity.
CVE-2026-28146 2 Unlimited-elements, Wordpress 2 Unlimited Elements For Elementor (free Widgets, Addons, Templates), Wordpress 2026-08-06 6.5 Medium
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
CVE-2026-66702 2 Rank Math Seo, Wordpress 2 Rank Math Seo, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-34501 1 Apache 1 Portable Runtime Utility 2026-08-06 7.5 High
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-66692 2 Colissimo, Wordpress 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress 2026-08-06 4.3 Medium
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-66695 2 Boldgrid, Wordpress 2 W3 Total Cache, Wordpress 2026-08-06 6.5 Medium
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-66703 2 Properfraction, Wordpress 2 Mailoptin, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.