| CVE-2025-7963 | MEDIUM | 6.4 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_e… | 2026-09-02 |
| CVE-2026-14828 | HIGH | 8.8 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Mana… | 2026-09-02 |
| CVE-2026-23583 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23584 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23585 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23586 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23587 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23588 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23589 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23590 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-23591 | NA | N/A | Rejected reason: Withdrawn by requester.… | 2026-09-02 |
| CVE-2026-75528 | HIGH | 7.2 | The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author U… | 2026-09-02 |
| CVE-2026-53683 | MEDIUM | 4.3 | reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (windo… | 2026-09-02 |
| CVE-2026-84175 | NA | N/A | In Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP… | 2026-09-02 |
| CVE-2026-18672 | HIGH | 7.5 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in Ra… | 2026-09-02 |
| CVE-2026-19219 | HIGH | 8.1 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request pa… | 2026-09-02 |
| CVE-2026-32773 | MEDIUM | 6.1 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job … | 2026-09-02 |
| CVE-2026-82958 | NA | N/A | In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service b… | 2026-09-02 |
| CVE-2026-66652 | MEDIUM | 5.4 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Tour allows Cross Site Request Forgery.
T… | 2026-09-02 |
| CVE-2026-81283 | HIGH | 8.8 | Subscriber PHP Object Injection in WP User Frontend <= 4.3.10 versions.… | 2026-09-02 |
| CVE-2026-81286 | CRITICAL | 9.3 | Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.… | 2026-09-02 |
| CVE-2026-81288 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Upsell Order Bump Offer for WooCommerce <= 3.1.5 versions.… | 2026-09-02 |
| CVE-2026-81289 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 … | 2026-09-02 |
| CVE-2026-81294 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.… | 2026-09-02 |
| CVE-2026-81769 | HIGH | 8.8 | Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation.
This is… | 2026-09-02 |
| CVE-2026-81770 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Interactive Geo Maps <= 1.6.30 versions.… | 2026-09-02 |
| CVE-2026-81771 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions.… | 2026-09-02 |
| CVE-2026-81772 | HIGH | 8.8 | Unauthenticated PHP Object Injection in Ninja Forms - Layout & Styles <= 3.0.31 versions.… | 2026-09-02 |
| CVE-2026-81774 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in WooCommerce Product Attachment <= 2.3.3 versions.… | 2026-09-02 |
| CVE-2026-81775 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions.… | 2026-09-02 |
| CVE-2026-82223 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.22 versions.… | 2026-09-02 |
| CVE-2026-83562 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions.… | 2026-09-02 |
| CVE-2026-84217 | MEDIUM | 5.4 | Missing Authorization vulnerability in Mamunur Rashid Classified Listing allows Accessing Functionality Not Pr… | 2026-09-02 |
| CVE-2026-84759 | HIGH | 7.1 | Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.… | 2026-09-02 |
| CVE-2026-84760 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in Ultimate Gift Cards For WooCommerce <= 3.2.9 versions.… | 2026-09-02 |
| CVE-2026-84764 | HIGH | 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in Simply Schedule Appointments <= 1.6.12.23 versions.… | 2026-09-02 |
| CVE-2026-84770 | HIGH | 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in Mang Board WP <= 2.3.8 versions.… | 2026-09-02 |
| CVE-2026-84771 | MEDIUM | 5.3 | Unauthenticated Insecure Direct Object References (IDOR) in PublishPress Permissions <= 4.8.3 versions.… | 2026-09-02 |
| CVE-2026-84772 | MEDIUM | 5.5 | Editor Server Side Request Forgery (SSRF) in Broken Link Checker <= 2.4.14 versions.… | 2026-09-02 |
| CVE-2026-84775 | MEDIUM | 5.3 | Unauthenticated Denial of Service Attack in Really Simple SSL <= 9.8.0 versions.… | 2026-09-02 |
| CVE-2026-84780 | MEDIUM | 5.3 | Unauthenticated Denial of Service Attack in WP Go Maps <= 10.1.08 versions.… | 2026-09-02 |
| CVE-2026-84781 | MEDIUM | 6.5 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions.… | 2026-09-02 |
| CVE-2026-84792 | MEDIUM | 4.3 | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-el… | 2026-09-02 |
| CVE-2026-84793 | MEDIUM | 4.8 | Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the si… | 2026-09-02 |
| CVE-2026-84794 | HIGH | 7.1 | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is … | 2026-09-02 |
| CVE-2026-84795 | CRITICAL | 9.8 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist fro… | 2026-09-02 |
| CVE-2026-84796 | HIGH | 8.8 | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolver… | 2026-09-02 |
| CVE-2026-84797 | MEDIUM | 6.3 | Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionD… | 2026-09-02 |
| CVE-2026-84798 | HIGH | 7.1 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsCo… | 2026-09-02 |
| CVE-2026-84799 | MEDIUM | 4.3 | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including a… | 2026-09-02 |