CVE Datenbank
Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.
CVE-2026-1764 - A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When proce
CVE-2026-12162 - Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager
CVE-2026-12161 - Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permis
CVE-2026-9262 - Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Vers
CVE-2026-9261 - Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9260 - Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-9259 - Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlie
CVE-2026-9258 - Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
CVE-2026-53430 - Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (
CVE-2026-48854 - Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauth
CVE-2026-48853 - Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabi
CVE-2026-48723 - The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on Browse
CVE-2026-48599 - Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authentica
CVE-2026-12205 - Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key
CVE-2026-5064 - Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC produ
CVE-2026-48714 - i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fasti
CVE-2026-48713 - Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when u
CVE-2026-48157 - Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versi
CVE-2026-48017 - DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reade
CVE-2026-12087 - Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_s
CVE-2026-11832 - Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The defa
CVE-2026-9691 - Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms,
CVE-2026-52703 - Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
CVE-2026-52702 - Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
CVE-2026-52700 - Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
CVE-2026-52699 - Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
CVE-2026-52697 - Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
CVE-2026-52695 - Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
CVE-2026-52694 - Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
CVE-2026-52693 - Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.
CVE-2026-52692 - Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.
CVE-2026-49781 - Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.
CVE-2026-49780 - Customer Privilege Escalation in Dokan <= 5.0.2 versions.
CVE-2026-49776 - Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatica
CVE-2026-49775 - Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.
CVE-2026-49773 - Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.
CVE-2026-49770 - Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.
CVE-2026-49769 - Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.
CVE-2026-49768 - Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.
CVE-2026-49766 - Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
CVE-2026-49765 - Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Eleme
CVE-2026-49764 - Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
CVE-2026-49763 - Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.
CVE-2026-49112 - Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
CVE-2026-49110 - Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.
CVE-2026-49109 - Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elem
CVE-2026-49106 - Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6
CVE-2026-49105 - Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidabl
CVE-2026-49104 - Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForm
CVE-2026-49085 - Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formida
CVE-2026-49083 - Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.
CVE-2026-49082 - Subscriber Sensitive Data Exposure in Chatway Live Chat – AI Chatbot, Customer Support, FAQ &a
CVE-2026-49078 - Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.
CVE-2026-49070 - Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.
CVE-2026-49068 - Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
CVE-2026-49067 - Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.
CVE-2026-49066 - Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
CVE-2026-49065 - Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.
CVE-2026-49063 - Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.
CVE-2026-49061 - Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.
CVE-2026-49056 - Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes a
CVE-2026-49055 - Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <=
CVE-2026-49043 - Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.
CVE-2026-48970 - Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.
CVE-2026-48966 - Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.
CVE-2026-48965 - Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.
CVE-2026-48964 - Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.
CVE-2026-48889 - Subscriber Privilege Escalation in Amelia <= 2.3 versions.
CVE-2026-48887 - Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.
CVE-2026-48886 - Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.
CVE-2026-48885 - Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.
CVE-2026-48883 - Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
CVE-2026-48882 - Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.
CVE-2026-48881 - Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.
CVE-2026-48880 - Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
CVE-2026-48878 - Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.
CVE-2026-48876 - Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.
CVE-2026-48874 - Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
CVE-2026-48873 - Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.
CVE-2026-48872 - Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
CVE-2026-48871 - Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.
CVE-2026-48870 - Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.
CVE-2026-48868 - Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
CVE-2026-48867 - Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.
CVE-2026-48838 - Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.
CVE-2026-48836 - Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
CVE-2026-48835 - Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
CVE-2026-48709 - OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and pr
CVE-2026-48708 - OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and pr
CVE-2026-48518 - MultiJuicer is used to run separate Juice Shop instances on a central kubernetes cluster without the
CVE-2026-48124 - Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Deskto
CVE-2026-47825 - Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxie
CVE-2026-47261 - Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a file
CVE-2026-45441 - Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
CVE-2026-45439 - Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
CVE-2026-45437 - Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.
CVE-2026-42775 - Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.
CVE-2026-42752 - Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.
CVE-2026-42743 - Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.
CVE-2026-42688 - Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.
CVE-2026-42687 - Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
CVE-2026-42686 - Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.
CVE-2026-42668 - Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versi
CVE-2026-42667 - Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
CVE-2026-42666 - Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
CVE-2026-42665 - Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
CVE-2026-42664 - Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce S
CVE-2026-42663 - Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.
CVE-2026-42662 - Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.
CVE-2026-42661 - Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
CVE-2026-42660 - Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.
CVE-2026-42659 - Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.
CVE-2026-42658 - Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.
CVE-2026-42657 - Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.
CVE-2026-42656 - Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.
CVE-2026-42655 - Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.
CVE-2026-42651 - Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.
CVE-2026-42650 - Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.
CVE-2026-42649 - Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.
CVE-2026-42640 - Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
CVE-2026-42639 - Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.
CVE-2026-42411 - Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
CVE-2026-42386 - Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.
CVE-2026-42384 - Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
CVE-2026-42381 - Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.
CVE-2026-42378 - Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.
CVE-2026-41556 - Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.
CVE-2026-40799 - Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.
CVE-2026-40798 - Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.
CVE-2026-40796 - Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.
CVE-2026-40795 - Subscriber Broken Access Control in Amelia <= 2.2 versions.
CVE-2026-40794 - Subscriber Broken Access Control in myCred <= 3.0.3 versions.
CVE-2026-40793 - Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.
CVE-2026-40792 - Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.
CVE-2026-40791 - Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.
CVE-2026-40790 - Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.
CVE-2026-40789 - Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
CVE-2026-40788 - Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.
CVE-2026-40787 - Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.
CVE-2026-40785 - Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
CVE-2026-40782 - Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.
CVE-2026-40781 - Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.
CVE-2026-40779 - Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.
CVE-2026-40776 - Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.
CVE-2026-40775 - Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.
CVE-2026-40774 - Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.
CVE-2026-40773 - Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.
CVE-2026-40772 - Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.
CVE-2026-40771 - Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.
CVE-2026-40770 - Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.
CVE-2026-40769 - Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File
CVE-2026-40767 - Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.
CVE-2026-40766 - Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.
CVE-2026-40762 - Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.
CVE-2026-40743 - Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.
CVE-2026-40741 - Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.
CVE-2026-40732 - Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.
CVE-2026-40727 - Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.
CVE-2026-39594 - Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.
CVE-2026-39591 - Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.
CVE-2026-39587 - Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.
CVE-2026-39584 - Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.
CVE-2026-39583 - Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
CVE-2026-39579 - Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
CVE-2026-39540 - Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.
CVE-2026-39534 - Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
CVE-2026-39533 - Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.
CVE-2026-39532 - Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.
CVE-2026-39530 - Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
CVE-2026-39527 - Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.
CVE-2026-39525 - Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.
CVE-2026-39524 - Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
CVE-2026-39519 - Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.
CVE-2026-39518 - Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.
CVE-2026-39515 - Subscriber Broken Access Control in Motors < 1.4.107 versions.
CVE-2026-39514 - Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.
CVE-2026-39513 - Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
CVE-2026-39512 - Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.
CVE-2026-39511 - Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
CVE-2026-39507 - Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.
CVE-2026-39503 - Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
CVE-2026-39502 - Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.
CVE-2026-39499 - Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6
CVE-2026-39498 - Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
CVE-2026-39493 - Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.
CVE-2026-39492 - Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.
CVE-2026-39491 - Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.
CVE-2026-39489 - Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.
CVE-2026-39481 - Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.
CVE-2026-39480 - Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.
CVE-2026-39478 - Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versio
CVE-2026-39474 - Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.
CVE-2026-39472 - Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.
CVE-2026-39471 - Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.
CVE-2026-39470 - Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.
CVE-2026-39468 - Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versio
CVE-2026-39465 - Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
CVE-2026-39463 - Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.
CVE-2026-39451 - Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.
CVE-2026-39450 - Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.
CVE-2026-39449 - Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.
CVE-2026-39447 - Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.
CVE-2026-39441 - Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.
CVE-2026-39435 - Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
CVE-2026-39434 - Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.
CVE-2026-34902 - Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.
CVE-2026-34901 - Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.
CVE-2026-34900 - Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.
CVE-2026-34898 - Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
CVE-2026-34892 - Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.
CVE-2026-34891 - Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
CVE-2026-34886 - Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
CVE-2026-27407 - Editor Privilege Escalation in AI Engine <= 3.4.9 versions.
CVE-2026-27333 - Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.
CVE-2026-27089 - Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.
CVE-2026-27053 - Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.
CVE-2026-25440 - Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.
CVE-2026-25425 - Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
CVE-2026-24637 - Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.
CVE-2026-23970 - Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.
CVE-2025-69332 - Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
CVE-2025-68872 - Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <=
CVE-2025-68851 - Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
CVE-2025-68840 - Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.
CVE-2025-68049 - Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.
CVE-2025-60175 - Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.
CVE-2025-59133 - Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
CVE-2026-54444 - Rejected reason: ]** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-49489. Reason:
CVE-2026-54296 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12075. Reason:
CVE-2026-54295 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12061. Reason:
CVE-2026-54294 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12072. Reason:
CVE-2026-54292 - Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12074. Reason:
CVE-2026-53705 - A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a special
CVE-2026-53704 - A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a
CVE-2026-53703 - A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a R
CVE-2026-52722 - A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream
CVE-2026-52721 - Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed P
CVE-2026-52720 - A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle
CVE-2026-52719 - An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad.
CVE-2026-52718 - A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The
CVE-2026-50892 - Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager
CVE-2026-50891 - Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to
CVE-2026-50890 - Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-gro
CVE-2026-50889 - An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a
CVE-2026-50888 - An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Ben
CVE-2026-50887 - A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink
CVE-2026-50886 - Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows at
CVE-2026-50885 - Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unaut
CVE-2026-50884 - Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administr
CVE-2026-50883 - An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows a
🏢 CVE nach Hersteller
Empfohlene Sicherheitstools
Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.