Search

Search Results (374142 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-66702 2 Rank Math Seo, Wordpress 2 Rank Math Seo, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-34501 1 Apache 1 Portable Runtime Utility 2026-08-06 7.5 High
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-66692 2 Colissimo, Wordpress 2 Colissimo Officiel : Méthodes De Livraison Pour Woocommerce, Wordpress 2026-08-06 4.3 Medium
Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-66695 2 Boldgrid, Wordpress 2 W3 Total Cache, Wordpress 2026-08-06 6.5 Medium
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
CVE-2026-66703 2 Properfraction, Wordpress 2 Mailoptin, Wordpress 2026-08-06 6.5 Medium
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
CVE-2026-6235 2 Sendmachine, Wordpress 2 Sendmachine For Wordpress, Wordpress 2026-08-06 9.8 Critical
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to overwrite the plugin's SMTP configuration, which can be leveraged to intercept all outbound emails from the site (including password reset emails).
CVE-2025-14843 3 Wizit, Woocommerce, Wordpress 3 Gateway For Woocommerce, Woocommerce, Wordpress 2026-08-06 5.3 Medium
The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' function. This makes it possible for unauthenticated attackers to cancel arbitrary WooCommerce orders by sending a crafted request with a valid order ID.
CVE-2026-69125 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason: This candidate is a duplicate of CVE-2026-67321. Notes: All CVE users should reference CVE-2026-67321 instead of this candidate.
CVE-2026-69124 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67320. Reason: This candidate is a duplicate of CVE-2026-67320. Notes: All CVE users should reference CVE-2026-67320 instead of this candidate.
CVE-2026-69123 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67319. Reason: This candidate is a duplicate of CVE-2026-67319. Notes: All CVE users should reference CVE-2026-67319 instead of this candidate.
CVE-2026-68948 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67318. Reason: This candidate is a duplicate of CVE-2026-67318. Notes: All CVE users should reference CVE-2026-67318 instead of this candidate.
CVE-2026-68947 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67317. Reason: This candidate is a duplicate of CVE-2026-67317. Notes: All CVE users should reference CVE-2026-67317 instead of this candidate.
CVE-2026-68946 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67315. Reason: This candidate is a duplicate of CVE-2026-67315. Notes: All CVE users should reference CVE-2026-67315 instead of this candidate.
CVE-2026-68944 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67316. Reason: This candidate is a duplicate of CVE-2026-67316. Notes: All CVE users should reference CVE-2026-67316 instead of this candidate.
CVE-2026-68943 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67314. Reason: This candidate is a duplicate of CVE-2026-67314. Notes: All CVE users should reference CVE-2026-67314 instead of this candidate.
CVE-2026-68942 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67313. Reason: This candidate is a duplicate of CVE-2026-67313. Notes: All CVE users should reference CVE-2026-67313 instead of this candidate.
CVE-2026-68941 2026-08-06 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason: This candidate is a duplicate of CVE-2026-67312. Notes: All CVE users should reference CVE-2026-67312 instead of this candidate.
CVE-2026-65559 2 Tychesoftwares, Wordpress 2 Order Delivery Date For Woocommerce, Wordpress 2026-08-06 7.2 High
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
CVE-2026-19045 1 Noctedefensor 1 Ludusmcp 2026-08-06 5.3 Medium
A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file src/utils/secretDialog.ts of the component get_credential_from_user. This manipulation of the argument Description causes command injection. It is possible to launch the attack on the local host. The project was informed of the problem early through an issue report but has not responded yet.
CVE-2026-65513 2 Nsquared, Wordpress 2 Simply Schedule Appointments, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.