Vulnerabilities (CVE)

Total 398795 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-65572 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-65575 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-66451 2026-08-12 N/A 6.5 MEDIUM
Unauthenticated Broken Authentication in WP Event SOlution <= 4.1.9 versions.
CVE-2026-61963 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-65565 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
CVE-2026-61964 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
CVE-2026-66686 2026-08-12 N/A 6.5 MEDIUM
Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.
CVE-2026-65541 2026-08-12 N/A 7.3 HIGH
Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVE-2026-65502 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
CVE-2026-65551 2026-08-12 N/A 7.5 HIGH
Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Breakdance: from n/a before 2.7.
CVE-2026-65556 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
CVE-2026-32469 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.
CVE-2026-66694 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
CVE-2026-66452 2026-08-12 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions.
CVE-2026-66663 2026-08-12 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
CVE-2026-65546 2026-08-12 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.
CVE-2026-65581 2026-08-12 N/A 9.8 CRITICAL
Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-65548 2026-08-12 N/A 9.9 CRITICAL
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
CVE-2026-28169 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.
CVE-2026-66685 2026-08-12 N/A 5.3 MEDIUM
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.