Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50589
Total
4065
Critical
14978
High
14744
Medium
CVE ID Severity Score Description Published
CVE-2026-13344 MEDIUM 4.8 The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, … Jul 30, 2026
CVE-2026-13330 MEDIUM 6.1 The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upload types, … Jul 30, 2026
CVE-2026-13178 HIGH 7.5 The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated users to create orders marked … Jul 30, 2026
CVE-2026-13145 MEDIUM 4.3 The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its customer account dashboard belongs to the current user, allowing … Jul 30, 2026
CVE-2026-13143 MEDIUM 5.3 The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before marking a booking paid, allowing … Jul 30, 2026
CVE-2026-12687 HIGH 7.5 The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registration, allowing unauthenticated users to … Jul 30, 2026
CVE-2026-12500 HIGH 7.5 The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress … Jul 30, 2026
CVE-2026-11881 MEDIUM 6.1 The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside an inline … Jul 30, 2026
CVE-2026-11870 MEDIUM 5.4 The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting … Jul 30, 2026
CVE-2026-11867 MEDIUM 6.5 The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and deletion operations, allowing authenticated … Jul 30, 2026
CVE-2026-11782 MEDIUM 5.9 The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that … Jul 30, 2026
CVE-2026-67248 UNKNOWN — A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before … Jul 30, 2026
CVE-2026-67247 UNKNOWN — A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated … Jul 30, 2026
CVE-2026-67246 UNKNOWN — A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before … Jul 30, 2026
CVE-2026-67245 UNKNOWN — A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated … Jul 30, 2026
CVE-2026-1360 HIGH 7.5 The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the … Jul 30, 2026
CVE-2026-16610 CRITICAL 9.8 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via … Jul 30, 2026
CVE-2026-14356 HIGH 8.8 The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin … Jul 30, 2026
CVE-2026-67244 UNKNOWN — A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through … Jul 30, 2026
CVE-2026-48449 CRITICAL 10.0 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. … Jul 30, 2026
CVE-2026-48448 HIGH 8.6 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to … Jul 30, 2026
CVE-2026-1982 MEDIUM 5.3 The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to … Jul 30, 2026
CVE-2026-18188 UNKNOWN — A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration or log data may … Jul 30, 2026
CVE-2026-18187 UNKNOWN — A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be included in an … Jul 30, 2026
CVE-2026-18186 UNKNOWN — A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration data may be written … Jul 30, 2026