Search
Search Results (389785 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-81805 | 2026-09-10 | 8.1 High | ||
| Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions. | ||||
| CVE-2026-81804 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions. | ||||
| CVE-2026-81801 | 2026-09-10 | 8.1 High | ||
| Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. | ||||
| CVE-2026-81800 | 2026-09-10 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions. | ||||
| CVE-2026-81799 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions. | ||||
| CVE-2026-81796 | 2026-09-10 | 7.3 High | ||
| Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions. | ||||
| CVE-2026-81794 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions. | ||||
| CVE-2026-81793 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. | ||||
| CVE-2026-81791 | 2026-09-10 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. | ||||
| CVE-2026-81789 | 2026-09-10 | 8.6 High | ||
| Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6 versions. | ||||
| CVE-2026-81787 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. | ||||
| CVE-2026-81786 | 2026-09-10 | 7.5 High | ||
| Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions. | ||||
| CVE-2026-81785 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. | ||||
| CVE-2026-81784 | 2026-09-10 | 8.1 High | ||
| Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions. | ||||
| CVE-2026-81782 | 2026-09-10 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions. | ||||
| CVE-2026-81275 | 2026-09-10 | 6.5 Medium | ||
| Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. | ||||
| CVE-2026-78536 | 2026-09-10 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. | ||||
| CVE-2026-66674 | 2026-09-10 | 5.6 Medium | ||
| Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | ||||
| CVE-2026-85310 | 2026-09-10 | 6.5 Medium | ||
| import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. | ||||
| CVE-2026-47887 | 2 Spring, Vmware | 2 Spring Framework, Spring Framework | 2026-09-10 | 6.1 Medium |
| A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | ||||
