Total
9924 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-49070 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions. | |||||
| CVE-2026-49065 | 2026-06-17 | N/A | 8.2 HIGH | ||
| Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions. | |||||
| CVE-2026-49054 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2. | |||||
| CVE-2026-49053 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |||||
| CVE-2026-49052 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |||||
| CVE-2026-49051 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6. | |||||
| CVE-2026-49047 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27. | |||||
| CVE-2026-49045 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11. | |||||
| CVE-2026-48973 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14. | |||||
| CVE-2026-48971 | 2026-06-17 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for WooCommerce: from n/a through 2.5.6. | |||||
| CVE-2026-48969 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions. | |||||
| CVE-2026-48887 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions. | |||||
| CVE-2026-48883 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions. | |||||
| CVE-2026-48881 | 2026-06-17 | N/A | 9.1 CRITICAL | ||
| Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions. | |||||
| CVE-2026-48873 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Montonio for WooCommerce <= 10.1.2 versions. | |||||
| CVE-2026-48835 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions. | |||||
| CVE-2026-48151 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under builderRoutes, but the generic authorization middleware skips authorization for all paths matching /api/webhooks/schema. As a result, an unauthenticated caller can update the body schema for a known webhook and mutate the corresponding automation trigger output schema. This vulnerability is fixed in 3.39.0. | |||||
| CVE-2026-48119 | 2026-06-17 | N/A | 7.1 HIGH | ||
| Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has been patched in version 2.0.12. | |||||
| CVE-2026-47197 | 2026-06-17 | N/A | N/A | ||
| Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can use the bot to moderate users above them in the Discord role hierarchy, as long as the bot itself outranks the target. This bypasses Discord’s normal role hierarchy protections and lets lower-ranked moderators ban, kick, timeout, untimeout, warn, or rename higher-ranked users. This issue has been patched in version 1.1.6. | |||||
| CVE-2026-47163 | 2026-06-17 | N/A | N/A | ||
| Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any guild member who can invoke slash commands can use /automod add, /automod remove, and /automod list because the command has no Discord default permission requirement and no runtime moderator permission check. An attacker can add a rule matching common text and make the bot delete other users’ messages. This issue has been patched in version 1.0.1. | |||||
