Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-49077

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.

PUBLISHED
Vendor
Tips and Tricks HQ
Product
WP eMember
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49076

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

PUBLISHED
Vendor
Jetimpex Inc.
Product
JetEngine
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49075

Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.

PUBLISHED
Vendor
Jetimpex Inc.
Product
JetEngine
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49074

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.

PUBLISHED
Vendor
Jetimpex Inc.
Product
JetEngine
Provider severity
HIGH
Conflicts
0

CVE-2026-49073

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection. This issue affects Directorist Booking: from n/a through 3.0.3.

PUBLISHED
Vendor
wpWax
Product
Directorist Booking
Provider severity
HIGH
Conflicts
0

CVE-2026-49072

Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.

PUBLISHED
Vendor
OPMC
Product
WooCommerce Anti-Fraud
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49071

Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions.

PUBLISHED
Vendor
OPMC
Product
WooCommerce Dropshipping
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49070

Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

PUBLISHED
Vendor
Knit Pay
Product
Knit Pay
Provider severity
HIGH
Conflicts
0

CVE-2026-4907

A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted element is the function sitemap.fetch of the file /sitemap of the component Endpoint. The manipulation of the argument url leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for aff

PUBLISHED
Vendor
Page-Replica
Product
Page Replica
Provider severity
MEDIUM
Conflicts
1

CVE-2026-49069

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21.

PUBLISHED
Vendor
WPZOOM
Product
WPZOOM Portfolio
Provider severity
HIGH
Conflicts
0

CVE-2026-49068

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

PUBLISHED
Vendor
RelyWP
Product
Coupon Affiliates
Provider severity
HIGH
Conflicts
0

CVE-2026-49067

Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

PUBLISHED
Vendor
yydevelopment
Product
Advanced 301 and 302 Redirect
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49066

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

PUBLISHED
Vendor
Conekta Group
Product
Conekta Payment Gateway
Provider severity
HIGH
Conflicts
0

CVE-2026-49065

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

PUBLISHED
Vendor
hippooo
Product
Hippoo Mobile App for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-49064

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Data. This issue affects GetPaid: from n/a through 2.8.49.

PUBLISHED
Vendor
Stiofan
Product
GetPaid
Provider severity
HIGH
Conflicts
0

CVE-2026-49063

Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.

PUBLISHED
Vendor
Webilia Inc.
Product
Listdom
Provider severity
HIGH
Conflicts
0

CVE-2026-49062

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Exploitation. This issue affects Faust.Js: from n/a through 1.8.7.

PUBLISHED
Vendor
WP Engine
Product
Faust.js
Provider severity
HIGH
Conflicts
0

CVE-2026-49061

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

PUBLISHED
Vendor
WPClever
Product
WPC Product Options for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-49060

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.

PUBLISHED
Vendor
Hippoo
Product
Hippoo Mobile App for WooCommerce
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4906

A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

PUBLISHED
Vendor
Tenda
Product
AC5
Provider severity
HIGH
Conflicts
2

CVE-2026-49059

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.

PUBLISHED
Vendor
Facebook
Product
Facebook for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49058

Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

PUBLISHED
Vendor
LoginPress
Product
LoginPress Pro
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49057

Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.

PUBLISHED
Vendor
EyeCix Technologies
Product
JobSearch
Provider severity
HIGH
Conflicts
0

CVE-2026-49056

Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions.

PUBLISHED
Vendor
WebToffee
Product
WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels
Provider severity
HIGH
Conflicts
0

CVE-2026-49055

Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions.

PUBLISHED
Vendor
Glen Don Mongaya
Product
Drag and Drop Multiple File Upload – Contact Form 7
Provider severity
HIGH
Conflicts
0

CVE-2026-49054

Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects The Post Grid: from n/a through 7.9.2.

PUBLISHED
Vendor
Mamunur Rashid
Product
The Post Grid
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49053

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

PUBLISHED
Vendor
Wpmet
Product
ElementsKit Elementor addons Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49052

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.

PUBLISHED
Vendor
Wpmet
Product
ElementsKit Elementor addons Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49051

Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and Date Remover: from n/a through 2.3.6.

PUBLISHED
Vendor
Prasad Kirpekar
Product
WP Meta and Date Remover
Provider severity
MEDIUM
Conflicts
0

CVE-2026-4905

A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsOOB of the component POST Request Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

PUBLISHED
Vendor
Tenda
Product
AC5
Provider severity
HIGH
Conflicts
2

CVE-2026-49049

The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.

PUBLISHED
Vendor
joomshaper.com
Product
Helix3 extension for Joomla
Provider severity
HIGH
Conflicts
0

CVE-2026-49048

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or parameterisation.

PUBLISHED
Vendor
joomcoder.com
Product
JoomCCK extension for Joomla
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-49047

Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27.

PUBLISHED
Vendor
DearHive
Product
DearFlip
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49046

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection. This issue affects Duplicate Page and Post: from n/a through 2.9.5.

PUBLISHED
Vendor
Arjun Thakur
Product
Duplicate Page and Post
Provider severity
HIGH
Conflicts
0

CVE-2026-49045

Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11.

PUBLISHED
Vendor
WP Media
Product
Adminimize
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49044

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue affects Advanced Custom Fields: Font Awesome Field: from n/a through 5.0.2.

PUBLISHED
Vendor
Justin Kruit
Product
Advanced Custom Fields: Font Awesome Field
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49043

Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions.

PUBLISHED
Vendor
WP Engine
Product
WP Migrate Lite
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49042

Improper Input Validation vulnerability in Apache Camel. This issue affects Apache Camel: from 4.8.0 through 4.18.2, from 4.19.0 through 4.20.0. Users are recommended to upgrade to version 4.18.3, 4.21.0, which fixes the issue.

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Camel
Provider severity
HIGH
Conflicts
0

CVE-2026-4904

A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/setcfm of the component POST Request Handler. Such manipulation of the argument funcpara1 leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
Tenda
Product
AC5
Provider severity
HIGH
Conflicts
2

CVE-2026-49035

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.

PUBLISHED
Vendor
MZ Automation
Product
libIEC61850
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-49033

The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.

PUBLISHED
Vendor
Labcenter
Product
Proteus
Provider severity
HIGH
Conflicts
1

CVE-2026-4903

A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. This manipulation of the argument PPPOEPassword causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used.

PUBLISHED
Vendor
Tenda
Product
AC5
Provider severity
HIGH
Conflicts
2

CVE-2026-4902

A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addressNat of the component POST Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
Tenda
Product
AC5
Provider severity
HIGH
Conflicts
2

CVE-2026-49017

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty buffer and re-reads, causing the proxy-server worker handling the request to become permanently unresponsive with increasing CPU and memory consumption. An authenticated attacker can systematically exhaust all proxy-server workers, resulting in denial of service. The defect was introduced in Swift 2.36

PUBLISHED
Vendor
OpenStack
Product
Swift
Provider severity
HIGH
Conflicts
0

CVE-2026-49014

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer without validating the attribute length. The attacker embeds the exploit as an oversized geometry attribute in a crafted NetCDF file. This achieves arbitrary code execution on the server running GDAL. This is in frmts/netcdf/netcdfsg.cpp.

PUBLISHED
Vendor
GDAL
Product
GDAL
Provider severity
HIGH
Conflicts
0

CVE-2026-4901

Hydrosystem Control System saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user.This issue was fixed in Hydrosystem Control System version 9.8.5

PUBLISHED
Vendor
Hydrosystem
Product
Control System
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49009

Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
LOW
Conflicts
1

CVE-2026-49002

Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and modifying configuration information.

PUBLISHED
Vendor
ZTE
Product
ZXUniPOS NDS-LTE
Provider severity
CRITICAL
Conflicts
0

CVE-2026-49001

Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampering with configuration data.

PUBLISHED
Vendor
ZTE
Product
ZXUniPOS NDS-LTE
Provider severity
MEDIUM
Conflicts
0

CVE-2026-49000

An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakage or tampering, such as hard-coded keys or the use of weak encryption algorithms.

PUBLISHED
Vendor
ZTE
Product
ZXUniPOS NDS-LTE
Provider severity
HIGH
Conflicts
0