Search

Search Results (33413 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-61961 2 Wordpress, Wpdeveloper 2 Wordpress, Embedpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-66708 2 Boldgrid, Wordpress 2 Total Upkeep, Wordpress 2026-08-06 8.2 High
Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.
CVE-2026-66709 2 Webappick, Wordpress 2 Ctx Feed, Wordpress 2026-08-06 9.1 Critical
Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
CVE-2026-66710 2 E2pdf, Wordpress 2 E2pdf, Wordpress 2026-08-06 8.1 High
Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.
CVE-2026-43622 1 Ggml-org 1 Llama.cpp 2026-08-06 7.8 High
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger this memory management mismatch to cause denial of service through process crashes or potentially achieve arbitrary code execution depending on allocator state.
CVE-2026-28178 2 Codesupplyco, Wordpress 2 Powerkit, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.
CVE-2026-32548 2 Surecart, Wordpress 2 Surecart, Wordpress 2026-08-06 5.3 Medium
Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.
CVE-2026-61982 2 Jp-secure, Wordpress 2 Siteguard Wp Plugin, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-65509 2 Wordpress, Wpdatatables 2 Wordpress, Wpdatatables 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-12605 2026-08-06 9.6 Critical
In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the token expires.
CVE-2026-65572 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-66665 2026-08-06 10 Critical
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
CVE-2026-65507 2 Sergey, Wordpress 2 Aiwu, Wordpress 2026-08-06 9.8 Critical
Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
CVE-2026-65573 2 Themerex, Wordpress 2 Abelle, Wordpress 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-66439 2 Berocket, Wordpress 2 Advanced Ajax Product Filters, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-65545 2 Jordy Meow, Wordpress 2 Ai-engine, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-65560 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
CVE-2026-65577 2026-08-06 9.8 Critical
Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-66457 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
CVE-2026-3430 2026-08-06 8.6 High
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.