Total
9918 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-66076 | 2026-07-02 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions. | |||||
| CVE-2026-50284 | 2026-07-02 | N/A | N/A | ||
| Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for the target folder. It never enforces deletePeerAssets:<volume-uid>, even though Assets::deleteFoldersByIds() cascades deletion to every descendant folder and every asset inside, regardless of the uploader's assigned privileges. A low-privilege user who has been granted folder-management rights on a shared volume can therefore destroy assets uploaded by other users (peer assets), bypassing the per-asset peer-permission check that the sibling actionDeleteAsset endpoint correctly applies. This issue has been fixed in versions 4.17.15 and 5.9.22. | |||||
| CVE-2026-12411 | 1 Canonical | 1 Lxd | 2026-07-02 | N/A | 8.4 HIGH |
| Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when security.devlxd.management.volumes is enabled. | |||||
| CVE-2026-12122 | 2026-07-02 | N/A | 5.3 MEDIUM | ||
| The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.11 via the get_single_symbol. This makes it possible for unauthenticated attackers to extract the full builder metadata and rendered HTML of any kirki_symbol post — including unpublished drafts — by supplying a sequential WordPress post ID. | |||||
| CVE-2026-11592 | 2026-07-02 | N/A | 4.3 MEDIUM | ||
| The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to overwrite plugin mail settings (from name and from email address), create audience lists, insert arbitrary contacts into those lists, create and overwrite newsletter broadcasts and post notifications, add workflows, and queue and dispatch mass email to arbitrary recipients. | |||||
| CVE-2026-57750 | 2026-07-02 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions. | |||||
| CVE-2025-69134 | 2026-07-02 | N/A | 7.5 HIGH | ||
| Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. | |||||
| CVE-2026-57760 | 2026-07-02 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29. | |||||
| CVE-2026-57353 | 2026-07-02 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions. | |||||
| CVE-2026-57730 | 2026-07-02 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in Flatsome <= 3.20.5 versions. | |||||
| CVE-2026-39448 | 2026-07-02 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions. | |||||
| CVE-2026-57685 | 2026-07-02 | N/A | 4.3 MEDIUM | ||
| Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions. | |||||
| CVE-2026-14156 | 1 Google | 1 Chrome | 2026-07-02 | N/A | 6.5 MEDIUM |
| Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low) | |||||
| CVE-2026-57721 | 2026-07-01 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6. | |||||
| CVE-2026-57720 | 2026-07-01 | N/A | 4.3 MEDIUM | ||
| Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2. | |||||
| CVE-2026-27409 | 2026-07-01 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13. | |||||
| CVE-2026-13484 | 1 Lfprojects | 1 Mlflow | 2026-07-01 | 4.6 MEDIUM | 5.0 MEDIUM |
| A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is regarded as difficult. The exploit has been disclosed to the public and may be used. A reply to the GitHub issue explains, that "[t]he labeling schema PR has not been merged yet. The auth handlers will be added before the release." | |||||
| CVE-2026-12113 | 2026-07-01 | N/A | 4.3 MEDIUM | ||
| The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.02 via the cpabc_appointments_filter_list. This makes it possible for authenticated attackers, with contributor-level access and above, to extract customer names, email addresses, phone numbers, appointment comments, and other booking personally identifiable information. | |||||
| CVE-2026-27435 | 2026-07-01 | N/A | 5.3 MEDIUM | ||
| Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33. | |||||
| CVE-2026-13468 | 2026-07-01 | N/A | 7.5 HIGH | ||
| The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to access and export the contents of any visualizer chart on the site — including charts in draft, private, pending, future, or trash status — as CSV, Excel, or HTML via the /wp-json/visualizer/v1/action/{chart}/{type}/ REST endpoint. This bypass is particularly impactful because the standard WordPress REST endpoint for the non-public 'visualizer' custom post type correctly enforces capability checks and returns HTTP 401 to unauthenticated callers, whereas this plugin-registered route circumvents that protection entirely. | |||||
