CVE IDSeverityCVSSDescriptionDate
CVE-2026-17563MEDIUM5.3The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when p…2026-09-02
CVE-2026-19698LOW3.5The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post bef…2026-09-02
CVE-2026-2688MEDIUM6.5The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded param…2026-09-02
CVE-2026-2811MEDIUM5.4The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient in…2026-09-02
CVE-2026-4357CRITICAL10.0The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plug…2026-09-02
CVE-2026-77009CRITICAL9.9The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which exe…2026-09-02
CVE-2026-77793MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration…2026-09-02
CVE-2026-77794MEDIUM5.3The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier …2026-09-02
CVE-2026-78153MEDIUM5.3The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking i…2026-09-02
CVE-2026-78584MEDIUM4.3Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via…2026-09-02
CVE-2026-78586MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via E…2026-09-02
CVE-2026-78587LOW3.1Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations v…2026-09-02
CVE-2026-78588MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via…2026-09-02
CVE-2026-78590HIGH7.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe…2026-09-02
CVE-2026-78591MEDIUM6.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe…2026-09-02
CVE-2026-78594MEDIUM4.9Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service…2026-09-02
CVE-2026-78598MEDIUM5.4Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure vi…2026-09-02
CVE-2026-78599MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet fe…2026-09-02
CVE-2026-78600LOW3.5Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privileg…2026-09-02
CVE-2026-78601MEDIUM5.5Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). …2026-09-02
CVE-2026-78602MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server…2026-09-02
CVE-2026-78604HIGH7.8Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege e…2026-09-02
CVE-2026-78609MEDIUM5.4Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification o…2026-09-02
CVE-2026-79989NAN/AThe vulnerability allows any authenticated user to change their own password without providing the current pas…2026-09-02
CVE-2026-79990NAN/ACraft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout …2026-09-02
CVE-2026-79991NAN/ACraft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout …2026-09-02
CVE-2026-81571MEDIUM4.8The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from be…2026-09-02
CVE-2026-82293MEDIUM4.3Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource con…2026-09-02
CVE-2026-82884MEDIUM6.8The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts b…2026-09-02
CVE-2026-82955NAN/AIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD i…2026-09-02
CVE-2026-83533MEDIUM5.3The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually …2026-09-02
CVE-2026-83547MEDIUM6.8The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before ou…2026-09-02
CVE-2026-8151MEDIUM5.4The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its set…2026-09-02
CVE-2026-19820NAN/AA vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link…2026-09-01
CVE-2026-18743LOW2.5A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration con…2026-09-01
CVE-2026-48932LOW3.7A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that …2026-09-01
CVE-2026-65643NAN/AEval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as…2026-09-01
CVE-2026-67394NAN/AA critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for …2026-09-01
CVE-2026-67395MEDIUM5.9A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to imprope…2026-09-01
CVE-2026-74837NAN/AAllocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una…2026-09-01
CVE-2026-75865CRITICAL9.8The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for W…2026-09-01
CVE-2026-77856NAN/AAllocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an una…2026-09-01
CVE-2026-77950NAN/AGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow…2026-09-01
CVE-2026-82730NAN/AIncorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read …2026-09-01
CVE-2026-82731NAN/AURL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an atta…2026-09-01
CVE-2026-82732NAN/AImproper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argum…2026-09-01
CVE-2026-82733NAN/AGeneration of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allow…2026-09-01
CVE-2026-19032MEDIUM5.3jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting t…2026-09-01
CVE-2026-82734NAN/AImproper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to subm…2026-09-01
CVE-2026-82735NAN/AUncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive re…2026-09-01
5 / 7715