Total CVEs

149,824

Critical Severity

4,834

High Severity

17,268

Last 7 Days

2,960
Quick preset (or use dates below)
Clear Filters
Showing 41 - 60 of 149,824 CVEs
CVE-2026-15016 MEDIUM - 6.4

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Readonly User Field via [pmpro_member_profile_edit] Shortcode in all versions up to, and including, 3.8.1 due to insufficient input saniti...

Vendor: strangerstudios
Product: Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions
Published: Jul 28, 2026
Source: NVD

Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios TecnolĂłgicos S.L.U. (version used at Resurrection Fest 2025), which employs cards based on MIFARE Classic technology (FM11RF08S). The cryptographic weakness of the authentication algo...

Published: Jul 28, 2026
Source: NVD

Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.

Vendor: Samsung Mobile
Product: Samsung Mobile Devices
Published: Jul 28, 2026
Source: NVD
CVE-2026-16774 MEDIUM - 5.3

The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce veri...

Vendor: quantumcloud
Product: WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
Published: Jul 28, 2026
Source: NVD
CVE-2026-16773 MEDIUM - 5.3

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full cha...

Vendor: quantumcloud
Product: WPBot – AI ChatBot for Live Support, Lead Generation, AI Services
Published: Jul 28, 2026
Source: NVD
CVE-2026-15444 MEDIUM - 4.9

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

Vendor: themeum
Product: Tutor LMS – eLearning and online course solution
Published: Jul 28, 2026
Source: NVD
CVE-2026-15411 MEDIUM - 5.3

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.0. This is due to the plugin not properly verifying that a user is authorized to perform a...

Vendor: wedevs
Product: StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
Published: Jul 28, 2026
Source: NVD
CVE-2026-15025 HIGH - 7.5

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.3.2 via the automator_google_contacts_fetch_labels, automator_mautic_segment_fetch, automator_mautic_tags_fetch, and a...

Vendor: uncannyowl
Product: Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin
Published: Jul 28, 2026
Source: NVD
CVE-2026-13440 HIGH - 7.2

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message_popup' parameter in all versions up to, and including, 2.1.0 due to insufficient input sanitizatio...

Vendor: wedevs
Product: StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
Published: Jul 28, 2026
Source: NVD
CVE-2026-13110 MEDIUM - 5.3

The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a missing capability check on the bogo_category_msg_create() AJAX handler, which is registered for both authenticated (wp_ajax_) and unauthenticated (wp_aja...

Vendor: wedevs
Product: StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
Published: Jul 28, 2026
Source: NVD

Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code execution for forms that include the signature field type.

Vendor: balbooa.com
Product: Balbooa Forms component for Joomla
Published: Jul 28, 2026
Source: NVD

A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash (../) sequences before resolving and serving the requested file. An authenticated attacker with admin privileges can use this vulnerability to read co...

Vendor: OpenSolution
Product: Quick.CMS
Published: Jul 28, 2026
Source: NVD

Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges can include arbitrary files located within the application's directory structure via a crafted HTTP request. Successful exploitation allows disclo...

Vendor: OpenSolution
Product: Quick.CMS
Published: Jul 28, 2026
Source: NVD

In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; however, the underlying language-deletion API endpoint does not enforce an equivalent server-side authorization check. As a result, an authenticated adm...

Vendor: OpenSolution
Product: Quick.CMS
Published: Jul 28, 2026
Source: NVD

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

Vendor: pretix GmbH
Product: pretix-girosolution
Published: Jul 28, 2026
Source: NVD

The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of an event in just a few clicks. This view did not properly check that the user has permission to change configuration for the given event. An attacker could use a well-...

Vendor: pretix GmbH
Product: pretix
Published: Jul 28, 2026
Source: NVD

A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a Matroska or WebM container file. The vulnerability is triggered by a boundary check that does not account for the full size of the data bei...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 28, 2026
Source: NVD

Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote attacker to exhaust connection process memory over HTTP/1.1. The HTTP/1.1 handler in cowboy_http enforces the max_headers limit by counting the number of distinct header names in ...

Vendor: ninenines
Product: cowboy
Published: Jul 28, 2026
Source: NVD

Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP/3 peer to exhaust memory on the vulnerable server (or client) and cause a denial of service. The HPACK and QPACK prefixed-integer decoder cow_hpack_common:dec_big_int/3 in src/co...

Vendor: ninenines
Product: cowlib
Published: Jul 28, 2026
Source: NVD
CVE-2026-58246 MEDIUM - 4.3

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate us...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server for ABAP
Published: Jul 28, 2026
Source: NVD