Search

Search Results (362114 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-19406 2 Easy-appointments, Wordpress 2 Easy Appointments, Wordpress 2026-08-19 N/A
The Easy Appointments WordPress plugin before 4.0.1 does not restrict one of its appointment-listing REST endpoints to the records belonging to the requesting user, allowing users with contributor-level access to read all bookings on the site, including customer names, schedules, and statuses.
CVE-2026-76235 1 Redhat 2 Enterprise Linux, Openshift Devspaces 2026-08-19 7.5 High
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
CVE-2026-8367 1 Aria2 Project 1 Aria2 2026-08-19 4.8 Medium
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
CVE-2026-66613 2026-08-19 9.8 Critical
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
CVE-2026-73184 2026-08-19 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
CVE-2026-73183 2026-08-19 9.3 Critical
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
CVE-2026-66668 2026-08-19 8.5 High
Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
CVE-2026-32552 2026-08-19 8.5 High
Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
CVE-2026-73391 2026-08-19 9.3 Critical
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
CVE-2026-73390 2026-08-19 9.8 Critical
Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
CVE-2026-73389 2026-08-19 9.8 Critical
Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
CVE-2026-73388 2026-08-19 9.3 Critical
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
CVE-2026-73387 2026-08-19 8.1 High
Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
CVE-2026-73386 2026-08-19 7.5 High
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.
CVE-2026-73385 2026-08-19 7.5 High
Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
CVE-2026-73384 2026-08-19 7.5 High
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
CVE-2026-73364 2026-08-19 9.8 Critical
Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.
CVE-2026-73363 2026-08-19 6.5 Medium
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.
CVE-2026-73354 2026-08-19 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
CVE-2026-73347 2026-08-19 9.8 Critical
Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.