Search

Search Results (402864 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-39788 2 Shamimsplugins, Wordpress-extensions 2 Front End Pm, Front End Pm 2026-10-06 6.5 Medium
Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions.
CVE-2026-39790 2 E4jvikwp, Wordpress-extensions 2 Vikrentcar, Vikrentcar 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in VikRentCar <= 1.4.6 versions.
CVE-2026-39792 2 Mitchell Bennis, Wordpress-extensions 2 Simple File List, Simple File List 2026-10-06 8.6 High
Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.
CVE-2026-39793 2 Nicu Micle, Wordpress-extensions 2 Simple Jwt Login, Simple Jwt Login 2026-10-06 8.8 High
Subscriber Broken Authentication in Simple JWT Login 4.0.0 versions.
CVE-2026-39794 2 Wclovers, Wordpress-extensions 2 Woocommerce Multivendor Marketplace, Woocommerce Multivendor Marketplace Rest Api 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WooCommerce Multivendor Marketplace – REST API <= 1.6.3 versions.
CVE-2026-39795 2 Brewlabs, Wordpress-extensions 2 Sendpress Newsletters, Sendpress Newsletters 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions.
CVE-2026-39796 2 Flipper Code, Wordpress-extensions 2 Advanced Posts Listing – Show Post List Easily, Advanced Posts Listing–show Post List Easily 2026-10-06 7.5 High
Unauthenticated Broken Access Control in Advanced Posts Listing – Show Post List Easily <= 1.0.8 versions.
CVE-2026-39797 2 Data443, Wordpress-extensions 2 Gdpr Framework By Data443, Gdpr Framework By Data443 2026-10-06 9.8 Critical
Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions.
CVE-2026-39798 2 Themetechmount, Wordpress-extensions 2 Truebooker, Truebooker 2026-10-06 6.5 Medium
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
CVE-2026-40806 2 Plugin-devs, Wordpress-extensions 2 Blog, Posts And Category Filter For Elementor, Blog Posts And Category Filter For Elementor 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Blog, Posts and Category Filter for Elementor <= 2.1.0 versions.
CVE-2026-40807 2 Aman, Wordpress-extensions 2 Cf7 Views – Complete Entry Management For Contact Form 7, Cf7 Views 2026-10-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.6 versions.
CVE-2026-41555 2 Weblizar, Wordpress-extensions 2 Newsletter Subscription Form – User Subscriptions Form, Capture Email, Newsletter Subscription Form – User Subscriptions Form, Capture Email 2026-10-06 9.3 Critical
Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1.5.9 versions.
CVE-2026-41559 2 Pluginjoy, Wordpress-extensions 2 Safesnap – Verified Wordpress Backup & Restore, Safesnap 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in SafeSnap – Verified WordPress Backup &amp; Restore <= 2.1.2 versions.
CVE-2026-41560 2 Wordpress-extensions, Wxdlabs 2 Wxd Backup Lite, Wxd Backup Lite 2026-10-06 7.5 High
Unauthenticated Broken Access Control in WXD Backup Lite <= 1.0.2 versions.
CVE-2026-41561 2 Adrian Lin, Wordpress-extensions 2 Museder Restoreone, Museder Restoreone 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Museder RestoreOne <= 2.7.276 versions.
CVE-2026-41562 2 Norvisgabriel, Wordpress-extensions 2 Norvis Backup, Norvis Backup 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Norvis Backup <= 1.1.0 versions.
CVE-2026-42413 2 Daftplug, Wordpress-extensions 2 Snapshotify, Snapshotify 2026-10-06 7.5 High
Unauthenticated Sensitive Data Exposure in Snapshotify &#8211; All-in-One Backup &amp; Restore &amp; Migrate <= 1.3.2 versions.
CVE-2026-98356 1 Linux 1 Linux Kernel 2026-10-06 7.0 High
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: check create_singlethread_workqueue() in DCB setup bnxt_re_init_dcb_wq() ignores a failed allocation. The async DCB handler later calls queue_work() on the NULL pointer.
CVE-2026-106497 2026-10-06 4.3 Medium
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1.
CVE-2026-106496 2026-10-06 3.1 Low
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.