Search
Search Results (92759 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-59499 | 1 Priority | 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions). | 2026-08-14 | 8.6 High |
| CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | ||||
| CVE-2026-59505 | 1 Priority | 1 Portal Generator Addon To Priority Erp (developed By Soft Solutions) | 2026-08-14 | 8.6 High |
| CWE-284: Improper Access Control | ||||
| CVE-2026-28003 | 2 Wordpress, Yonifre | 2 Wordpress, Maspik – Spam Blacklist | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions. | ||||
| CVE-2026-28156 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in Do Lasso <= 358 versions. | ||||
| CVE-2026-28157 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.5 High |
| Subscriber Path Traversal in Do Lasso <= 358 versions. | ||||
| CVE-2026-28158 | 2 Lasso Analytics, Inc., Wordpress | 2 Do Lasso, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions. | ||||
| CVE-2026-28161 | 2 Aonetheme, Wordpress | 2 Service Finder Booking, Wordpress | 2026-08-14 | 8.8 High |
| Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | ||||
| CVE-2026-28168 | 2 Imran Tauqeer, Wordpress | 2 Cubewp, Wordpress | 2026-08-14 | 8.5 High |
| Subscriber SQL Injection in CubeWP <= 1.1.30 versions. | ||||
| CVE-2026-28186 | 2 Themefic, Wordpress | 2 Travelfic Toolkit, Wordpress | 2026-08-14 | 8.1 High |
| Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions. | ||||
| CVE-2026-65580 | 2 Bracketweb, Wordpress | 2 Agrion, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Agrion <= 1.0.0 versions. | ||||
| CVE-2026-66431 | 2 Woompaloompa, Wordpress | 2 Bitcoin Lightning Payment Gateway For Woocommerce (via Clink), Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) <= 1.0.7 versions. | ||||
| CVE-2026-66462 | 2 Bookingwp, Wordpress | 2 Woocommerce Appointments, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions. | ||||
| CVE-2026-66463 | 2 Hassan Fakih, Wordpress | 2 Icarry, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | ||||
| CVE-2026-66466 | 2 Wedevs, Wordpress | 2 Storegrowth: Smart Sales Booster For Woocommerce | Bogo, Upsells, Direct Checkout, Quick View, Side Cart, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions. | ||||
| CVE-2026-66468 | 2 Powerfulwp, Wordpress | 2 Local Delivery Drivers For Woocommerce, Wordpress | 2026-08-14 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions. | ||||
| CVE-2026-66469 | 2 Afonso Matos, Wordpress | 2 Arvow Ai Seo Writer, Wordpress | 2026-08-14 | 7.5 High |
| Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | ||||
| CVE-2026-66661 | 2 Onokazu, Wordpress | 2 Directories Pro, Wordpress | 2026-08-14 | 7.7 High |
| Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. | ||||
| CVE-2026-16101 | 1 Silabs.com | 1 Wiseconnect | 2026-08-14 | 8.8 High |
| Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below | ||||
| CVE-2026-19291 | 1 Silabs.com | 1 Wiseconnect | 2026-08-14 | 8.8 High |
| Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below. | ||||
| CVE-2026-19292 | 1 Silabs.com | 1 Wiseconnect | 2026-08-14 | 8.8 High |
| Re-pairing with a legitimate device can use a lower security level than previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below. | ||||