Export limit exceeded: 372987 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 39939 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (39939 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-19052 2 Prosolution, Wordpress 2 Prosolution Wp Client, Wordpress 2026-08-14 4.3 Medium
The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX actions, and the nonce they rely on is published on its public frontend, allowing any authenticated user, such as a subscriber, to trigger an administrative data synchronisation and to clear the ProSolution WP Client WordPress plugin before 2.0.9's activity records.
CVE-2026-27345 2 Magepeople, Wordpress 2 Taxi Booking Manager For Woocommerce, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
CVE-2026-66430 2 Codepress It Solutions Llc, Wordpress 2 Visitor Traffic Real Time Statistics Pro, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-66461 2 Smepay, Wordpress 2 Smepay:upi Gateway For Woocommerce, Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
CVE-2026-66658 2 Mvp Themes, Wordpress 2 Reviewer, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
CVE-2026-73346 2 Mailchimp, Wordpress 2 Mailchimp For Woocommerce, Wordpress 2026-08-14 7.6 High
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2026-73353 2 Revolut, Wordpress 2 Revolut Gateway For Woocommerce, Wordpress 2026-08-14 5.3 Medium
Unauthenticated Broken Access Control in Revolut Gateway for WooCommerce < 4.22.10 versions.
CVE-2026-72825 1 Getgrav 1 Grav 2026-08-14 7.6 High
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces requirePermission('api.config.write') followed by a bare isSuperAdmin() check instead of requireSuper(). Because isSuperAdmin() reads access.api.super directly and never consults api_key_scopes, a least-privilege API key scoped to api.config.write minted on a super account passes the gate, allowing an attacker to append attacker-chosen tokens to the security.twig_sandbox allowlist (persisted to user/config/security.yaml). Widening the allowlist turns any subsequent Twig-in-content render into an SSTI/RCE sink.
CVE-2026-72823 1 Getgrav 1 Grav 2026-08-14 5.4 Medium
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method checks isSuperAdmin() and returns early before invoking requirePermission(), so the api_key_scopes cap (enforced only in requirePermission()) is skipped. As a result, any scoped API key minted on a super account can bypass its scope restrictions when calling the baseline() and reset() operations (e.g. POST /api/v1/demo/reset), allowing it to capture the demo baseline or force a demo reset. Impact is bounded to demo-engine control and is conditional on demo mode being configured with writable resources.
CVE-2026-19787 1 Sourcecodester 1 Air Cargo Management System 2026-08-14 4.7 Medium
A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-58416 1 Gitea 1 Gitea Open Source Git Server 2026-08-14 7.1 High
Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)
CVE-2026-28156 2 Lasso Analytics, Inc., Wordpress 2 Do Lasso, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-28159 2 Aonetheme, Wordpress 2 Service Finder Booking, Wordpress 2026-08-14 6.5 Medium
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVE-2026-28168 2 Imran Tauqeer, Wordpress 2 Cubewp, Wordpress 2026-08-14 8.5 High
Subscriber SQL Injection in CubeWP <= 1.1.30 versions.
CVE-2026-28186 2 Themefic, Wordpress 2 Travelfic Toolkit, Wordpress 2026-08-14 8.1 High
Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
CVE-2026-61978 2 Webhosting4ugr, Wordpress 2 Secure Card Gateway For Epay Paycenter (piraeus Bank), Wordpress 2026-08-14 6.5 Medium
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
CVE-2026-66431 2 Woompaloompa, Wordpress 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress 2026-08-14 7.5 High
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions.
CVE-2026-66446 2 If-so Dynamic Content, Wordpress 2 If-so Dynamic Content Personalization, Wordpress 2026-08-14 9.3 Critical
Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
CVE-2026-66455 2 Rockiger, Wordpress 2 Reactpress, Wordpress 2026-08-14 6 Medium
Subscriber Broken Access Control in ReactPress <= 3.4.0 versions.
CVE-2026-66459 2 Space Codes, Wordpress 2 Ai For Seo, Wordpress 2026-08-14 6.5 Medium
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.