Total CVEs

138,591

Critical Severity

3,578

High Severity

12,841

Last 7 Days

1,641
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 121 - 140 of 34,996 CVEs
CVE-2020-37255 HIGH - 7.5

WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies a...

Vendor: Wptimecapsule
Product: Time Capsule Plugin
Published: Jun 20, 2026
Source: NVD
CVE-2019-25763 CRITICAL - 9.8

WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-s...

Vendor: Ultimatebeaver
Product: Ultimate Addons for Beaver Builder
Published: Jun 20, 2026
Source: NVD

A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

Vendor: icagenda.com
Product: iCagenda extension for Joomla
Published: Jun 20, 2026
Source: NVD

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

Vendor: joomshaper.net
Product: SP LMS extension for Joomla
Published: Jun 20, 2026
Source: NVD

A vulnerability in the SP Page Builder for Joomla allows the upload of arbitrary files for unauthenticated users, ultimately resulting in PHP code upload and execution.

Vendor: joomshaper.net
Product: SP Page Builder extension for Joomla
Published: Jun 20, 2026
Source: NVD
CVE-2026-12119 MEDIUM - 6.5

The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization check on the 'frontmanage' shortcode attribute in all versions up to, and including, 6.3.7. This makes it possible for authenticated attackers, with contributor-level acce...

Vendor: eemitch
Product: Simple File List
Published: Jun 20, 2026
Source: NVD
CVE-2026-11912 HIGH - 7.5

The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable...

Vendor: eemitch
Product: Simple File List
Published: Jun 20, 2026
Source: NVD
CVE-2026-11911 HIGH - 7.5

The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, whic...

Vendor: eemitch
Product: Simple File List
Published: Jun 20, 2026
Source: NVD
CVE-2026-9843 HIGH - 8.1

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbit...

Published: Jun 20, 2026
Source: NVD

Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator. Downstream callers run strlen(...

Published: Jun 20, 2026
Source: NVD
CVE-2026-56216 HIGH - 8.8

Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting empty limits. Attackers with a compromised app-limited key can create an unrestricted key with org-wide access to resources ...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56215 HIGH - 8.3

Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim's corporate SSO email, causing the provision-user endpo...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56214 HIGH - 7.5

Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allows unauthenticated attackers to enumerate organizations and disclose billing status using the public sb_publishable key. Attackers can invoke these endpo...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-56213 MEDIUM - 5.3

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into version_meta for any app_id. Attackers can exploit this by calling the RPC endp...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD

Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their own account. The application fails to verify the initiator'...

Vendor: Capgo
Product: Capgo
Published: Jun 20, 2026
Source: NVD
CVE-2026-11551 CRITICAL - 9.8

The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to ...

Vendor: wpmudev
Product: Branda โ€“ White Label & Branding, Free Login Page Customizer
Published: Jun 20, 2026
Source: NVD
CVE-2026-56082 HIGH - 7.5

Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated att...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56081 CRITICAL - 9.1

Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account cl...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56080 MEDIUM - 4.9

Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat the account as non-c...

Vendor: Cap-go
Product: capgo
Published: Jun 19, 2026
Source: NVD
CVE-2026-56079 MEDIUM - 6.5

Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs. Attackers can query the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing s...

Vendor: Capgo
Product: Capgo
Published: Jun 19, 2026
Source: NVD