Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.

PUBLISHED
Vendor
WBW Plugins
Product
Product Filter by WBW
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39493

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.

PUBLISHED
Vendor
NSquared
Product
Simply Schedule Appointments
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39492

Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

PUBLISHED
Vendor
Flipper Code – WordPress Development Company
Product
WP Maps
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39491

Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

PUBLISHED
Vendor
artbees
Product
JupiterX Core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39490

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

PUBLISHED
Vendor
artbees
Product
JupiterX Core
Provider severity
HIGH
Conflicts
0

CVE-2026-3949

A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.

PUBLISHED
Vendor
strukturag
Product
libheif
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-39489

Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.

PUBLISHED
Vendor
WP Chill
Product
Download Monitor
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39488

Missing Authorization vulnerability in SureCart SureCart surecart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SureCart: from n/a through <= 4.0.2.

PUBLISHED
Vendor
SureCart
Product
SureCart
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39487

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ameliabooking Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through <= 2.1.1.

PUBLISHED
Vendor
ameliabooking
Product
Amelia
Provider severity
HIGH
Conflicts
0

CVE-2026-39486

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Chill Download Monitor download-monitor allows Blind SQL Injection.This issue affects Download Monitor: from n/a through <= 5.1.8.

PUBLISHED
Vendor
WP Chill
Product
Download Monitor
Provider severity
HIGH
Conflicts
1

CVE-2026-39485

Missing Authorization vulnerability in embedplus Youtube Embed Plus youtube-embed-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Youtube Embed Plus: from n/a through <= 14.2.4.

PUBLISHED
Vendor
embedplus
Product
Youtube Embed Plus
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39484

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00.

PUBLISHED
Vendor
John Darrel
Product
Hide My WP Ghost
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39483

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidekazu Ishikawa VK All in One Expansion Unit vk-all-in-one-expansion-unit allows Stored XSS.This issue affects VK All in One Expansion Unit: from n/a through <= 9.113.3.

PUBLISHED
Vendor
Hidekazu Ishikawa
Product
VK All in One Expansion Unit
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39482

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PublishPress Post Expirator post-expirator allows DOM-Based XSS.This issue affects Post Expirator: from n/a through <= 4.9.4.

PUBLISHED
Vendor
PublishPress
Product
Post Expirator
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39481

Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.

PUBLISHED
Vendor
WP Chill
Product
Modula Image Gallery
Provider severity
HIGH
Conflicts
0

CVE-2026-39480

Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.

PUBLISHED
Vendor
Inisev
Product
Backup Migration
Provider severity
HIGH
Conflicts
0

CVE-2026-39479

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force OttoKit suretriggers allows Blind SQL Injection.This issue affects OttoKit: from n/a through <= 1.1.20.

PUBLISHED
Vendor
Brainstorm Force
Product
OttoKit
Provider severity
HIGH
Conflicts
0

CVE-2026-39478

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.

PUBLISHED
Vendor
Eli Scheetz
Product
Anti-Malware Security and Brute-Force Firewall
Provider severity
HIGH
Conflicts
0

CVE-2026-39477

Missing Authorization vulnerability in Brainstorm Force CartFlows cartflows allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CartFlows: from n/a through <= 2.2.3.

PUBLISHED
Vendor
Brainstorm Force
Product
CartFlows
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39476

Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.10.1.

PUBLISHED
Vendor
Syed Balkhi
Product
User Feedback
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39475

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Blind SQL Injection.This issue affects User Feedback: from n/a through <= 1.10.1.

PUBLISHED
Vendor
Syed Balkhi
Product
User Feedback
Provider severity
HIGH
Conflicts
1

CVE-2026-39474

Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.

PUBLISHED
Vendor
metaphorcreations
Product
Post Duplicator
Provider severity
HIGH
Conflicts
0

CVE-2026-39473

Insertion of Sensitive Information Into Sent Data vulnerability in Pär Thernström Simple History simple-history allows Retrieve Embedded Sensitive Data.This issue affects Simple History: from n/a through <= 5.24.0.

PUBLISHED
Vendor
Pär Thernström
Product
Simple History
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39472

Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

PUBLISHED
Vendor
WP Overnight
Product
WooCommerce PDF Invoices & Packing Slips
Provider severity
HIGH
Conflicts
0

CVE-2026-39471

Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

PUBLISHED
Vendor
ShortPixel
Product
ShortPixel Image Optimizer
Provider severity
HIGH
Conflicts
0

CVE-2026-39470

Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.

PUBLISHED
Vendor
Brainstorm Force
Product
WooCommerce Cart Abandonment Recovery
Provider severity
HIGH
Conflicts
0

CVE-2026-39469

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Softaculous PageLayer pagelayer allows Retrieve Embedded Sensitive Data.This issue affects PageLayer: from n/a through <= 2.0.8.

PUBLISHED
Vendor
Softaculous
Product
PageLayer
Provider severity
MEDIUM
Conflicts
1

CVE-2026-39468

Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.

PUBLISHED
Vendor
eLightUp
Product
Meta Box – WordPress Custom Fields Framework
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39467

Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through 3.106.0.

PUBLISHED
Vendor
MetaSlider
Product
Responsive Slider by MetaSlider
Provider severity
HIGH
Conflicts
0

CVE-2026-39466

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Broken Link Checker broken-link-checker allows Blind SQL Injection.This issue affects Broken Link Checker: from n/a through <= 2.4.7.

PUBLISHED
Vendor
WPMU DEV - Your All-in-One WordPress Platform
Product
Broken Link Checker
Provider severity
HIGH
Conflicts
0

CVE-2026-39465

Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.

PUBLISHED
Vendor
MetaSlider
Product
Responsive Slider by MetaSlider
Provider severity
CRITICAL
Conflicts
0

CVE-2026-39464

Server-Side Request Forgery (SSRF) vulnerability in SeedProd Coming Soon Page, Under Construction & Maintenance Mode by SeedProd coming-soon allows Server Side Request Forgery.This issue affects Coming Soon Page, Under Construction & Maintenance Mode by SeedProd: from n/a through <= 6.19.8.

PUBLISHED
Vendor
SeedProd
Product
Coming Soon Page, Under Construction & Maintenance Mode by SeedProd
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39463

Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.

PUBLISHED
Vendor
ManageWP
Product
ManageWP Worker
Provider severity
HIGH
Conflicts
0

CVE-2026-39462

A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the password update was successful; however, the system may continue to accept the previous or default credentials, demonstrating that the password-change process is not consistently enforced. Even after

PUBLISHED
Vendor
SenseLive
Product
X3050
Provider severity
CRITICAL, HIGH
Conflicts
1

CVE-2026-39461

libcasper(3) communicates with helper processes via UNIX domain sockets, and uses the select(2) system call to wait for data to become available. However, it does not verify that its socket descriptor fits within select(2)'s descriptor set size limit of FD_SETSIZE (1024). An attacker able to cause an application using libcasper(3) to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, may trigger stack corr

PUBLISHED
Vendor
FreeBSD
Product
FreeBSD
Provider severity
HIGH
Conflicts
0

CVE-2026-3946

A vulnerability was detected in PHPEMS 11.0. The affected element is an unknown function of the file /index.php?ask=app-ask. Performing a manipulation of the argument askcontent results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.

PUBLISHED
Vendor
n/a
Product
PHPEMS
Provider severity
LOW, MEDIUM
Conflicts
2

CVE-2026-39459

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create configuration objects that allow running arbitrary commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2026-39458

When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2026-39457

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size limit of FD_SETSIZE (1024). An attacker who is able to force a libnv application to allocate large file descriptors, e.g., by opening many descriptors and executing a program which is not careful to close them upon startup, can trigger stack corruption. If the target application is setuid-root, then

PUBLISHED
Vendor
FreeBSD
Product
FreeBSD
Provider severity
HIGH
Conflicts
0

CVE-2026-39455

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the available file descriptors.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

PUBLISHED
Vendor
F5
Product
BIG-IP
Provider severity
HIGH
Conflicts
1

CVE-2026-39454

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the administrative privilege.

PUBLISHED
Vendor
Sky Co.,LTD., Sky Co.,LTD.
Product
SKYMEC IT Manager, SKYSEA Client View
Provider severity
HIGH
Conflicts
2

CVE-2026-39451

Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.

PUBLISHED
Vendor
jgwhite33
Product
WP Google Review Slider
Provider severity
MEDIUM
Conflicts
0

CVE-2026-39450

Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.

PUBLISHED
Vendor
Aman
Product
FunnelKit Automations
Provider severity
HIGH
Conflicts
0

CVE-2026-3945

An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1.11.3 allows an unauthenticated remote attacker to cause a denial of service (DoS). The issue occurs because chunk size values are parsed using strtol() without properly validating overflow conditions (e.g., errno == ERANGE). A crafted chunk size such as 0x7fffffffffffffff (LONG_MAX) bypasses the existing validation check (chunklen < 0), leading to a signed integer overflow du

PUBLISHED
Vendor
tinyproxy
Product
tinyproxy
Provider severity
HIGH
Conflicts
1

CVE-2026-39449

Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.

PUBLISHED
Vendor
IT Path Solutions
Product
Contact Form to Any API
Provider severity
HIGH
Conflicts
0

CVE-2026-39448

Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.

PUBLISHED
Vendor
CoderPress
Product
NOWPayments for WooCommerce
Provider severity
HIGH
Conflicts
0

CVE-2026-39447

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.

PUBLISHED
Vendor
NSquared
Product
Simply Schedule Appointments
Provider severity
HIGH
Conflicts
0

CVE-2026-39446

Unauthenticated PHP Object Injection in Kapee < 1.7.0 versions.

PUBLISHED
Vendor
PressLayouts
Product
Kapee
Provider severity
HIGH
Conflicts
0

CVE-2026-39445

Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions.

PUBLISHED
Vendor
PressLayouts
Product
Alukas
Provider severity
HIGH
Conflicts
0

CVE-2026-39443

Unauthenticated PHP Object Injection in EmallShop <= 2.4.21 versions.

PUBLISHED
Vendor
PressLayouts
Product
EmallShop
Provider severity
HIGH
Conflicts
0