Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-32374

Missing Authorization vulnerability in raratheme The Minimal the-minimal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Minimal: from n/a through <= 1.2.9.

PUBLISHED
Vendor
raratheme
Product
The Minimal
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32373

Missing Authorization vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Alert Order Notifications: from n/a through <= 3.9.0.

PUBLISHED
Vendor
Cozy Vision
Product
SMS Alert Order Notifications
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32372

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Retrieve Embedded Sensitive Data.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 3.2.4.

PUBLISHED
Vendor
RadiusTheme
Product
ShopBuilder – Elementor WooCommerce Builder Addons
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32371

Missing Authorization vulnerability in raratheme Elegant Pink elegant-pink allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elegant Pink: from n/a through <= 1.3.3.

PUBLISHED
Vendor
raratheme
Product
Elegant Pink
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32370

Missing Authorization vulnerability in raratheme Influencer influencer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Influencer: from n/a through <= 1.1.7.

PUBLISHED
Vendor
raratheme
Product
Influencer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3237

In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.

PUBLISHED
Vendor
Octopus Deploy
Product
Octopus Server
Provider severity
LOW
Conflicts
1

CVE-2026-32369

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Medilink-Core medilink-core allows PHP Local File Inclusion.This issue affects Medilink-Core: from n/a through < 2.0.7.

PUBLISHED
Vendor
RadiusTheme
Product
Medilink-Core
Provider severity
HIGH
Conflicts
0

CVE-2026-32368

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind SQL Injection.This issue affects Geo to Lat: from n/a through <= 1.0.19.

PUBLISHED
Vendor
delphiknight
Product
Geo to Lat
Provider severity
HIGH
Conflicts
0

CVE-2026-32367

Improper Control of Generation of Code ('Code Injection') vulnerability in Yannick Lefebvre Modal Dialog modal-dialog allows Remote Code Inclusion.This issue affects Modal Dialog: from n/a through <= 3.5.16.

PUBLISHED
Vendor
Yannick Lefebvre
Product
Modal Dialog
Provider severity
CRITICAL
Conflicts
0

CVE-2026-32366

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Categories collapsing-categories allows Blind SQL Injection.This issue affects Collapsing Categories: from n/a through <= 3.0.9.

PUBLISHED
Vendor
robfelty
Product
Collapsing Categories
Provider severity
HIGH
Conflicts
0

CVE-2026-32365

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in robfelty Collapsing Archives collapsing-archives allows Blind SQL Injection.This issue affects Collapsing Archives: from n/a through <= 3.0.7.

PUBLISHED
Vendor
robfelty
Product
Collapsing Archives
Provider severity
HIGH
Conflicts
0

CVE-2026-32364

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in redqteam Turbo Manager turbo-manager allows PHP Local File Inclusion.This issue affects Turbo Manager: from n/a through < 4.0.8.

PUBLISHED
Vendor
redqteam
Product
Turbo Manager
Provider severity
HIGH
Conflicts
0

CVE-2026-32363

Missing Authorization vulnerability in Funlus Oy WPLifeCycle free-php-version-info allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPLifeCycle: from n/a through <= 3.3.1.

PUBLISHED
Vendor
Funlus Oy
Product
WPLifeCycle
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32362

Missing Authorization vulnerability in activity-log.com WP Sessions Time Monitoring Full Automatic activitytime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Sessions Time Monitoring Full Automatic: from n/a through <= 1.1.3.

PUBLISHED
Vendor
activity-log.com
Product
WP Sessions Time Monitoring Full Automatic
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32361

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marketing Fire Editorial Calendar editorial-calendar allows DOM-Based XSS.This issue affects Editorial Calendar: from n/a through <= 3.9.0.

PUBLISHED
Vendor
Marketing Fire
Product
Editorial Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32360

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in richplugins Rich Showcase for Google Reviews widget-google-reviews allows Stored XSS.This issue affects Rich Showcase for Google Reviews: from n/a through <= 6.9.4.3.

PUBLISHED
Vendor
richplugins
Product
Rich Showcase for Google Reviews
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3236

In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.

PUBLISHED
Vendor
Octopus Deploy
Product
Octopus Server
Provider severity
LOW
Conflicts
0

CVE-2026-32359

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: from n/a through <= 1.2.3.

PUBLISHED
Vendor
bPlugins
Product
Icon List Block
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32358

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdevelop Booking Calendar booking allows Blind SQL Injection.This issue affects Booking Calendar: from n/a through <= 10.14.15.

PUBLISHED
Vendor
wpdevelop
Product
Booking Calendar
Provider severity
HIGH
Conflicts
0

CVE-2026-32357

Server-Side Request Forgery (SSRF) vulnerability in Katsushi Kawamori Simple Blog Card simple-blog-card allows Server Side Request Forgery.This issue affects Simple Blog Card: from n/a through <= 2.37.

PUBLISHED
Vendor
Katsushi Kawamori
Product
Simple Blog Card
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32356

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robosoft Robo Gallery robo-gallery allows DOM-Based XSS.This issue affects Robo Gallery: from n/a through <= 5.1.2.

PUBLISHED
Vendor
robosoft
Product
Robo Gallery
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32355

Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.

PUBLISHED
Vendor
Crocoblock
Product
JetEngine
Provider severity
HIGH
Conflicts
0

CVE-2026-32354

Insertion of Sensitive Information Into Sent Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Retrieve Embedded Sensitive Data.This issue affects WpEvently: from n/a through < 5.1.9.

PUBLISHED
Vendor
magepeopleteam
Product
WpEvently
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32353

Server-Side Request Forgery (SSRF) vulnerability in MailerPress Team MailerPress mailerpress allows Server Side Request Forgery.This issue affects MailerPress: from n/a through <= 1.4.2.

PUBLISHED
Vendor
MailerPress Team
Product
MailerPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32352

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor allows DOM-Based XSS.This issue affects Elementor Website Builder: from n/a through <= 3.35.5.

PUBLISHED
Vendor
Elementor
Product
Elementor Website Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32351

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blubrry PowerPress Podcasting powerpress allows Stored XSS.This issue affects PowerPress Podcasting: from n/a through <= 11.15.13.

PUBLISHED
Vendor
blubrry
Product
PowerPress Podcasting
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32350

Missing Authorization vulnerability in wpradiant Chocolate House chocolate-house allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chocolate House: from n/a through <= 1.1.5.

PUBLISHED
Vendor
wpradiant
Product
Chocolate House
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32349

Server-Side Request Forgery (SSRF) vulnerability in Andy Fragen Embed PDF Viewer embed-pdf-viewer allows Server Side Request Forgery.This issue affects Embed PDF Viewer: from n/a through <= 2.4.7.

PUBLISHED
Vendor
Andy Fragen
Product
Embed PDF Viewer
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32348

Missing Authorization vulnerability in MadrasThemes MAS Videos masvideos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MAS Videos: from n/a through <= 1.3.2.

PUBLISHED
Vendor
MadrasThemes
Product
MAS Videos
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32347

Missing Authorization vulnerability in raratheme Restaurant and Cafe restaurant-and-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restaurant and Cafe: from n/a through <= 1.2.5.

PUBLISHED
Vendor
raratheme
Product
Restaurant and Cafe
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32346

Missing Authorization vulnerability in raratheme Travel Agency travel-agency allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel Agency: from n/a through <= 1.5.5.

PUBLISHED
Vendor
raratheme
Product
Travel Agency
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32345

Missing Authorization vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Perfect Portfolio: from n/a through <= 1.2.4.

PUBLISHED
Vendor
raratheme
Product
Perfect Portfolio
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32344

Cross-Site Request Forgery (CSRF) vulnerability in desertthemes Corpiva corpiva allows Cross Site Request Forgery.This issue affects Corpiva: from n/a through <= 1.0.96.

PUBLISHED
Vendor
desertthemes
Product
Corpiva
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32343

Cross-Site Request Forgery (CSRF) vulnerability in Magazine3 Easy Table of Contents easy-table-of-contents allows Cross Site Request Forgery.This issue affects Easy Table of Contents: from n/a through <= 2.0.80.

PUBLISHED
Vendor
Magazine3
Product
Easy Table of Contents
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32342

Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.1.2.

PUBLISHED
Vendor
Ays Pro
Product
Quiz Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32341

Missing Authorization vulnerability in raratheme Benevolent benevolent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Benevolent: from n/a through <= 1.3.9.

PUBLISHED
Vendor
raratheme
Product
Benevolent
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32340

Missing Authorization vulnerability in raratheme Business One Page business-one-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Business One Page: from n/a through <= 1.3.2.

PUBLISHED
Vendor
raratheme
Product
Business One Page
Provider severity
MEDIUM
Conflicts
0

CVE-2026-3234

A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeenc() function, allows a remote attacker to bypass input validation. By injecting CRLF sequences into the cluster configuration, an attacker can corrupt the response body of INFO endpoint responses. Exploitation requires network access to the MCMP protocol port, but no authentication is needed.

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 9, Red Hat JBoss Core Services, Red Hat JBoss Core Services, Red Hat Enterprise Linux 10
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32339

Missing Authorization vulnerability in raratheme Bakes And Cakes bakes-and-cakes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bakes And Cakes: from n/a through <= 1.2.9.

PUBLISHED
Vendor
raratheme
Product
Bakes And Cakes
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32338

Missing Authorization vulnerability in raratheme Construction Landing Page construction-landing-page allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Construction Landing Page: from n/a through <= 1.4.1.

PUBLISHED
Vendor
raratheme
Product
Construction Landing Page
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32337

Missing Authorization vulnerability in raratheme Preschool and Kindergarten preschool-and-kindergarten allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Preschool and Kindergarten: from n/a through <= 1.2.5.

PUBLISHED
Vendor
raratheme
Product
Preschool and Kindergarten
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32336

Missing Authorization vulnerability in raratheme Rara Business rara-business allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rara Business: from n/a through <= 1.3.0.

PUBLISHED
Vendor
raratheme
Product
Rara Business
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32335

Missing Authorization vulnerability in raratheme The Conference the-conference allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Conference: from n/a through <= 1.2.5.

PUBLISHED
Vendor
raratheme
Product
The Conference
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32334

Missing Authorization vulnerability in raratheme JobScout jobscout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobScout: from n/a through <= 1.1.7.

PUBLISHED
Vendor
raratheme
Product
JobScout
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32332

Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Form: from n/a through <= 2.7.9.

PUBLISHED
Vendor
Ays Pro
Product
Easy Form
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32331

Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Textmetrics: from n/a through <= 3.6.4.

PUBLISHED
Vendor
Israpil
Product
Textmetrics
Provider severity
MEDIUM
Conflicts
1

CVE-2026-32330

Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Request Forgery.This issue affects Photo Gallery by 10Web: from n/a through <= 1.8.37.

PUBLISHED
Vendor
10Web
Product
Photo Gallery by 10Web
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32329

Missing Authorization vulnerability in Ays Pro Advanced Related Posts advanced-related-posts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Related Posts: from n/a through <= 1.9.1.

PUBLISHED
Vendor
Ays Pro
Product
Advanced Related Posts
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32328

Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery.This issue affects Lemmony: from n/a through < 1.7.1.

PUBLISHED
Vendor
shufflehound
Product
Lemmony
Provider severity
MEDIUM
Conflicts
0

CVE-2026-32326

SHARP routers do not perform authentication for some web APIs. The device information may be retrieved without authentication. If the administrative password of the device is left as the initial one, the device may be taken over.

PUBLISHED
Vendor
Sharp Corporation, Sharp Corporation, Sharp Corporation, Sharp Corporation, Sharp Corporation, Sharp Corporation, Sharp Corporation, Sharp Corporation
Product
Wi-Fi STATION SH-52A, Wi-Fi STATION SH-54C, 5G Mobile Router SH-U01, home 5G HR02, Wi-Fi STATION SH-52B, home 5G HR01, Pocket WiFi 5G A503SH, Speed Wi-Fi 5G X01
Provider severity
MEDIUM
Conflicts
2