CVE Datenbank

Durchsuchbare Datenbank mit Sicherheitslücken. Filtere nach Hersteller, Schweregrad oder Zeitraum.

Zurücksetzen
28000 CVEs gefunden (Seite 88/112)

CVE-2026-12293 - Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Th

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-12292 - Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 15

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-12291 - Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firef

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-12290 - Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-12289 - Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 1

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-8484 - A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-40750 - Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store al

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-12225 - syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an auth

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-10829 - A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series v

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-10828 - A format string vulnerability has been found in the "alias" parameter of the Serial Param configurat

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-8442 - The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions u

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-8176 - The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerab

🏢 Aws 📅 16.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-5416 - Due to the improper neutralization of special elements used in a name parameter a low privileged rem

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-54198 - Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-54197 - Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-54191 - Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-54190 - Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-52715 - Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-52714 - Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-52712 - Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 7.6
7.6

CVE-2026-52711 - Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49774 - Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station al

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-49772 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-40809 - Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Conf

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-39581 - Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-39574 - Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39490 - Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-39437 - Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-2381 - The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modificati

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-10825 - A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and han

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 0.0
0.0

CVE-2025-68045 - Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-8444 - The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]'

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-46331 - In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial CO

🏢 Linux 📅 16.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-10093 - The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Store

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 6.4
6.4

CVE-2025-9912 - Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation

🏢 Linux 📅 16.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-9187 - The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post delet

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-8443 - The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 's

🏢 Oracle 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-6933 - The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing auth

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-5149 - The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-50255 - Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and ea

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-10780 - The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-10635 - On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core

🏢 F5 📅 16.6.2026 📊 CVSS: 6.3
6.3

CVE-2025-10262 - Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format v

🏢 Linux 📅 16.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-6964 - The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all v

🏢 Wordpress 📅 16.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-7273 - A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versi

🏢 Zyxel 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-42014 - A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Securi

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.6
6.6

CVE-2026-1767 - A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracke

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 5.6
5.6

CVE-2026-1766 - A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifical

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 5.6
5.6

CVE-2026-1765 - A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tr

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 5.6
5.6

CVE-2026-1764 - A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When proce

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 5.6
5.6

CVE-2026-12162 - Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 5.5
5.5

CVE-2026-12161 - Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permis

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-9262 - Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Vers

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-9261 - Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.8
6.8

CVE-2026-9260 - Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.2
6.2

CVE-2026-9259 - Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlie

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-9258 - Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

🏢 Sonstige 📅 16.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-53430 - Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48854 - Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauth

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48853 - Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabi

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48723 - The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on Browse

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.8
7.8

CVE-2026-48599 - Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authentica

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-12205 - Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-5064 - Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC produ

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-48714 - i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fasti

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-48713 - Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when u

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-48157 - Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versi

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.1
6.1

CVE-2026-48017 - DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reade

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-12087 - Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_s

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-11832 - Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The defa

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-9691 - Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms,

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-52703 - Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.6
9.6

CVE-2026-52702 - Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-52700 - Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-52699 - Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-52697 - Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-52695 - Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-52694 - Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-52693 - Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-52692 - Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49781 - Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49780 - Customer Privilege Escalation in Dokan <= 5.0.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-49776 - Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatica

🏢 Wordpress 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-49775 - Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-49773 - Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-49770 - Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49769 - Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49768 - Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49766 - Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-49765 - Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Eleme

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49764 - Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49763 - Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49112 - Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49110 - Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49109 - Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elem

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49106 - Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49105 - Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidabl

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49104 - Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForm

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49085 - Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formida

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-49083 - Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49082 - Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &a

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.4
7.4

CVE-2026-49078 - Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49070 - Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49068 - Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49067 - Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-49066 - Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49065 - Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.2
8.2

CVE-2026-49063 - Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-49061 - Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49056 - Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes a

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-49055 - Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <=

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-49043 - Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 4.7
4.7

CVE-2026-48970 - Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-48966 - Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-48965 - Subscriber Sensitive Data Exposure in XCloner <= 4.8.6 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-48964 - Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.

🏢 Wordpress 📅 15.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-48889 - Subscriber Privilege Escalation in Amelia <= 2.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-48887 - Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-48886 - Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-48885 - Unauthenticated Cross Site Scripting (XSS) in HollerBox <= 2.3.10.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-48883 - Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48882 - Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-48881 - Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-48880 - Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-48878 - Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.4.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-48876 - Unauthenticated Cross Site Scripting (XSS) in Stop Spammers <= 2026.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-48874 - Subscriber SQL Injection in GamiPress <= 7.8.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-48873 - Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48872 - Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48871 - Unauthenticated Cross Site Scripting (XSS) in MW WP Form <= 5.1.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-48870 - Subscriber Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.62 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-48868 - Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48867 - Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.1.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-48838 - Unauthenticated Cross Site Scripting (XSS) in Post SMTP <= 3.6.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-48836 - Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 10.0
10.0

CVE-2026-48835 - Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48709 - OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and pr

🏢 Oracle 📅 15.6.2026 📊 CVSS: 3.7
3.7

CVE-2026-48708 - OliveTin gives access to predefined shell commands from a web interface. In versions 3000.0.0 and pr

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-48518 - MultiJuicer is used to run separate Juice Shop instances on a central kubernetes cluster without the

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 4.3
4.3

CVE-2026-48124 - Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Deskto

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 0.0
0.0

CVE-2026-47825 - Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxie

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.6
8.6

CVE-2026-47261 - Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a file

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-45441 - Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-45439 - Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-45437 - Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-42775 - Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-42752 - Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42743 - Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42688 - Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42687 - Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42686 - Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-42668 - Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versi

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42667 - Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42666 - Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42665 - Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-42664 - Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce S

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.2
8.2

CVE-2026-42663 - Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42662 - Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42661 - Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-42660 - Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42659 - Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42658 - Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-42657 - Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-42656 - Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42655 - Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 5.9
5.9

CVE-2026-42651 - Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-42650 - Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-42649 - Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-42640 - Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-42639 - Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-42411 - Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-42386 - Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-42384 - Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-42381 - Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-42378 - Subscriber Broken Authentication in WP Full Stripe Free <= 8.4.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-41556 - Subscriber Cross Site Scripting (XSS) in ProfilePress <= 4.16.13 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40799 - Unauthenticated Broken Authentication in Simple Cloudflare Turnstile <= 1.38.0 versions.

🏢 Cloudflare 📅 15.6.2026 📊 CVSS: 5.3
5.3

CVE-2026-40798 - Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-40796 - Subscriber Sensitive Data Exposure in WPPizza <= 3.19.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40795 - Subscriber Broken Access Control in Amelia <= 2.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40794 - Subscriber Broken Access Control in myCred <= 3.0.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40793 - Subscriber Broken Access Control in Groundhogg < 4.4.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40792 - Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-40791 - Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-40790 - Subscriber Sensitive Data Exposure in WP SMS <= 7.2.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40789 - Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40788 - Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-40787 - Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.0.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-40785 - Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-40782 - Unauthenticated Broken Access Control in WPAdverts <= 2.3.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40781 - Unauthenticated Broken Authentication in ReviewX <= 2.3.6 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40779 - Contributor Arbitrary File Deletion in Link Library <= 7.8.8 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.7
7.7

CVE-2026-40776 - Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.8 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40775 - Unauthenticated Broken Access Control in Royal MCP <= 1.4.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.3
7.3

CVE-2026-40774 - Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40773 - Subscriber Broken Access Control in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.9 versions.

🏢 Wordpress 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40772 - Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 10.0
10.0

CVE-2026-40771 - Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-40770 - Unauthenticated Cross Site Scripting (XSS) in Coupon Affiliates <= 7.5.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-40769 - Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi &#8211; Save Entries, File

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.6
8.6

CVE-2026-40767 - Unauthenticated Broken Access Control in wpForo Forum < 3.0.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40766 - Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.5
8.5

CVE-2026-40762 - Unauthenticated SQL Injection in WPGraphQL < 2.11.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40743 - Unauthenticated Broken Access Control in Tutor LMS <= 3.9.7 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-40741 - Unauthenticated Broken Access Control in Redsys for WooCommerce Light <= 7.0.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-40732 - Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-40727 - Sales Representative Arbitrary File Deletion in Groundhogg <= 4.4 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.7
7.7

CVE-2026-39594 - Subscriber Broken Access Control in Ultra Addons for WPForms <= 1.0.11 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.4
6.4

CVE-2026-39591 - Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.9
9.9

CVE-2026-39587 - Unauthenticated Privilege Escalation in WP BASE Booking <= 5.9.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.1
8.1

CVE-2026-39584 - Subscriber Broken Access Control in RepairBuddy <= 4.1132 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-39583 - Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.8
9.8

CVE-2026-39579 - Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-39540 - Subscriber Cross Site Scripting (XSS) in Shipment Tracker for Woocommerce <= 1.5.3.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-39534 - Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-39533 - Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-39532 - Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-39530 - Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39527 - Subscriber Arbitrary File Upload in WpStream < 4.11.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 5.4
5.4

CVE-2026-39525 - Unauthenticated Broken Access Control in Booking Activities <= 1.16.48.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-39524 - Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-39519 - Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39518 - Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-39515 - Subscriber Broken Access Control in Motors < 1.4.107 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-39514 - Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-39513 - Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-39512 - Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39511 - Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39507 - Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-39503 - Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-39502 - Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39499 - Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-39498 - Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-39493 - Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39492 - Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.3
9.3

CVE-2026-39491 - Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 6.5
6.5

CVE-2026-39489 - Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 4.4
4.4

CVE-2026-39481 - Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-39480 - Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.5
7.5

CVE-2026-39478 - Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versio

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-39474 - Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 8.8
8.8

CVE-2026-39472 - Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-39471 - Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-39470 - Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.2
7.2

CVE-2026-39468 - Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versio

🏢 Wordpress 📅 15.6.2026 📊 CVSS: 6.8
6.8

CVE-2026-39465 - Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 9.1
9.1

CVE-2026-39463 - Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-39451 - Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.

🏢 Google 📅 15.6.2026 📊 CVSS: 6.3
6.3

CVE-2026-39450 - Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1

CVE-2026-39449 - Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.

🏢 Sonstige 📅 15.6.2026 📊 CVSS: 7.1
7.1
«« « Zurück Seite 88 von 112 Weiter » »»

🏢 CVE nach Hersteller

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.