Search
Search Results (380220 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-74951 | 1 Mozilla | 1 Firefox | 2026-08-18 | 6.5 Medium |
| Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154. | ||||
| CVE-2026-74046 | 2026-08-18 | 4.9 Medium | ||
| Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.py that allows authenticated cluster peers to exhaust memory by supplying a malicious synchronization archive without decompressed size limits. Attackers holding a valid cluster Fernet key can upload a small, highly compressed zip bomb archive that forces wazuh-clusterd on the master node to decompress the full payload into memory, causing memory exhaustion and service disruption. | ||||
| CVE-2026-74015 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||||
| CVE-2026-74009 | 2 Razorpay, Wordpress | 2 Razorpay For Woocommerce, Wordpress | 2026-08-18 | 5.3 Medium |
| Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. | ||||
| CVE-2026-74006 | 2026-08-18 | 4.3 Medium | ||
| Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions. | ||||
| CVE-2026-74003 | 2 Rometheme, Wordpress | 2 Romethemeform For Elementor, Wordpress | 2026-08-18 | 4.3 Medium |
| Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions. | ||||
| CVE-2026-73995 | 2 Wordpress, Wpeverest | 2 Wordpress, User Registration | 2026-08-18 | 5.4 Medium |
| Subscriber Broken Authentication in User Registration <= 5.2.6 versions. | ||||
| CVE-2026-73404 | 2026-08-18 | 6.5 Medium | ||
| Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | ||||
| CVE-2026-73398 | 2 Papaki, Wordpress | 2 Piraeus Bank Woocommerce Payment Gateway, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | ||||
| CVE-2026-73396 | 2026-08-18 | 7.1 High | ||
| Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | ||||
| CVE-2026-73392 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | ||||
| CVE-2026-73382 | 2 Geminilabs, Wordpress | 2 Site Reviews, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | ||||
| CVE-2026-73379 | 2026-08-18 | 6.5 Medium | ||
| Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | ||||
| CVE-2026-73377 | 2026-08-18 | 7.5 High | ||
| Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. | ||||
| CVE-2026-73367 | 2 Supsystic, Wordpress | 2 Easy Google Maps, Wordpress | 2026-08-18 | 7.2 High |
| Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | ||||
| CVE-2026-73365 | 2026-08-18 | 9.3 Critical | ||
| Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | ||||
| CVE-2026-73360 | 2 Premio, Wordpress | 2 Chaty Pro, Wordpress | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | ||||
| CVE-2026-73358 | 2 Wordpress, Wp.insider | 2 Wordpress, Affiliates Manager | 2026-08-18 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | ||||
| CVE-2026-73352 | 2 Nexcess, Wordpress | 2 Givewp, Wordpress | 2026-08-18 | 6.5 Medium |
| Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. | ||||
| CVE-2026-73350 | 2 Psm Plugins, Wordpress | 2 Supportcandy, Wordpress | 2026-08-18 | 8.2 High |
| Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. | ||||