Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-25340

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind SQL Injection.This issue affects Jobmonster: from n/a through < 4.8.4.

PUBLISHED
Vendor
NooTheme
Product
Jobmonster
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2534

A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET&section=ptest_bandwidth. The manipulation of the argument bandwidth leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Comfast
Product
CF-N1 V2
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25339

Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms: from n/a through <= 1.9.8.7.

PUBLISHED
Vendor
Syed Balkhi
Product
Contact Form by WPForms
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25338

Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4.

PUBLISHED
Vendor
Ays Pro
Product
AI ChatBot with ChatGPT and Content Generator by AYS
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25337

Cross-Site Request Forgery (CSRF) vulnerability in wpcoachify Coachify coachify allows Cross Site Request Forgery.This issue affects Coachify: from n/a through <= 1.1.5.

PUBLISHED
Vendor
wpcoachify
Product
Coachify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25336

Missing Authorization vulnerability in wpcoachify Coachify coachify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Coachify: from n/a through <= 1.1.5.

PUBLISHED
Vendor
wpcoachify
Product
Coachify
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25335

Missing Authorization vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Secure Copy Content Protection and Content Locking: from n/a through <= 5.0.0.

PUBLISHED
Vendor
Ays Pro
Product
Secure Copy Content Protection and Content Locking
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25334

Incorrect Privilege Assignment vulnerability in wordpresschef Salon Booking System Pro salon-booking-plugin-pro allows Privilege Escalation.This issue affects Salon Booking System Pro: from n/a through < 10.30.12.

PUBLISHED
Vendor
wordpresschef
Product
Salon Booking System Pro
Provider severity
HIGH
Conflicts
0

CVE-2026-25333

Missing Authorization vulnerability in peregrinethemes Shopwell shopwell allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shopwell: from n/a through <= 1.0.11.

PUBLISHED
Vendor
peregrinethemes
Product
Shopwell
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25332

Missing Authorization vulnerability in Fahad Mahmood Endless Posts Navigation endless-posts-navigation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Endless Posts Navigation: from n/a through <= 2.2.9.

PUBLISHED
Vendor
Fahad Mahmood
Product
Endless Posts Navigation
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25331

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows DOM-Based XSS.This issue affects WP Activity Log: from n/a through <= 5.5.4.

PUBLISHED
Vendor
Melapress
Product
WP Activity Log
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25330

Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1.

PUBLISHED
Vendor
PublishPress
Product
PublishPress Authors
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2533

A flaw has been found in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/tosei_datasend.php. Executing a manipulation of the argument adr_txt_1 can lead to command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Tosei
Product
Self-service Washing Machine
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2026-25329

Missing Authorization vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4.

PUBLISHED
Vendor
ExpressTech Systems
Product
Quiz And Survey Master
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25328

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce allows Path Traversal.This issue affects Product File Upload for WooCommerce: from n/a through <= 2.2.4.

PUBLISHED
Vendor
add-ons.org
Product
Product File Upload for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25327

Missing Authorization vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.9.

PUBLISHED
Vendor
Rustaurius
Product
Five Star Restaurant Reservations
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25326

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.

PUBLISHED
Vendor
cmsmasters
Product
CMSMasters Content Composer
Provider severity
HIGH
Conflicts
0

CVE-2026-25325

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Retrieve Embedded Sensitive Data.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through <= 4.7.8.

PUBLISHED
Vendor
rtCamp
Product
rtMedia for WordPress, BuddyPress and bbPress
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25324

Authorization Bypass Through User-Controlled Key vulnerability in ExpressTech Systems Quiz And Survey Master quiz-master-next allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quiz And Survey Master: from n/a through <= 10.3.4.

PUBLISHED
Vendor
ExpressTech Systems
Product
Quiz And Survey Master
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25323

Missing Authorization vulnerability in MiKa OSM osm allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects OSM: from n/a through <= 6.1.12.

PUBLISHED
Vendor
MiKa
Product
OSM
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25322

Cross-Site Request Forgery (CSRF) vulnerability in PublishPress PublishPress Revisions revisionary allows Cross Site Request Forgery.This issue affects PublishPress Revisions: from n/a through <= 3.7.22.

PUBLISHED
Vendor
PublishPress
Product
PublishPress Revisions
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25321

Missing Authorization vulnerability in PSM Plugins SupportCandy supportcandy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SupportCandy: from n/a through <= 3.4.4.

PUBLISHED
Vendor
PSM Plugins
Product
SupportCandy
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25320

Missing Authorization vulnerability in Cool Plugins Elementor Contact Form DB sb-elementor-contact-form-db allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Contact Form DB: from n/a through <= 2.1.3.

PUBLISHED
Vendor
Cool Plugins
Product
Elementor Contact Form DB
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2532

A vulnerability was detected in lintsinghua DeepAudit up to 3.0.3. This issue affects some unknown processing of the file backend/app/api/v1/endpoints/embedding_config.py of the component IP Address Handler. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.0.4 and 3.1.0 is capable of addressing this issue. The patch is named da853fdd8cbe9d42053b45d83f25708ba29b8b27. It is suggested to upgrade the affected com

PUBLISHED
Vendor
lintsinghua
Product
DeepAudit
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25319

Cross-Site Request Forgery (CSRF) vulnerability in wpzita Zita Elementor Site Library zita-site-library allows Cross Site Request Forgery.This issue affects Zita Elementor Site Library: from n/a through <= 1.6.6.

PUBLISHED
Vendor
wpzita
Product
Zita Elementor Site Library
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25318

Missing Authorization vulnerability in Wisernotify team WiserReview Product Reviews for WooCommerce wiser-review allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WiserReview Product Reviews for WooCommerce: from n/a through <= 2.9.

PUBLISHED
Vendor
Wisernotify team
Product
WiserReview Product Reviews for WooCommerce
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25317

Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.9.0.

PUBLISHED
Vendor
tychesoftwares
Product
Print Invoice & Delivery Notes for WooCommerce
Provider severity
HIGH
Conflicts
1

CVE-2026-25316

Deserialization of Untrusted Data vulnerability in Brainstorm Force CartFlows cartflows allows Object Injection.This issue affects CartFlows: from n/a through <= 2.1.19.

PUBLISHED
Vendor
Brainstorm Force
Product
CartFlows
Provider severity
HIGH
Conflicts
0

CVE-2026-25315

Missing Authorization vulnerability in hcaptcha hCaptcha for WP hcaptcha-for-forms-and-more allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects hCaptcha for WP: from n/a through <= 4.21.1.

PUBLISHED
Vendor
hcaptcha
Product
hCaptcha for WP
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25314

Missing Authorization vulnerability in WP Messiah TOP Table Of Contents top-table-of-contents allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TOP Table Of Contents: from n/a through <= 1.3.31.

PUBLISHED
Vendor
WP Messiah
Product
TOP Table Of Contents
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25313

Missing Authorization vulnerability in Shahjahan Jewel FluentForm fluentform allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FluentForm: from n/a through <= 6.1.14.

PUBLISHED
Vendor
Shahjahan Jewel
Product
FluentForm
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25312

Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through <= 4.2.8.3.

PUBLISHED
Vendor
Metagauss
Product
EventPrime
Provider severity
HIGH
Conflicts
0

CVE-2026-25311

Missing Authorization vulnerability in 10up Autoshare for Twitter autoshare-for-twitter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoshare for Twitter: from n/a through <= 2.3.1.

PUBLISHED
Vendor
10up
Product
Autoshare for Twitter
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25310

Server-Side Request Forgery (SSRF) vulnerability in Alobaidi Extend Link extend-link allows Server Side Request Forgery.This issue affects Extend Link: from n/a through <= 2.0.0.

PUBLISHED
Vendor
Alobaidi
Product
Extend Link
Provider severity
MEDIUM
Conflicts
0

CVE-2026-2531

A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 74d6f0fd4b630218519a700fbee1c05c7fd4b1ed. It is best practice to apply a patch to resolve this issue.

PUBLISHED
Vendor
n/a
Product
MindsDB
Provider severity
MEDIUM
Conflicts
1

CVE-2026-25309

Missing Authorization vulnerability in PublishPress PublishPress Authors publishpress-authors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Authors: from n/a through <= 4.10.1.

PUBLISHED
Vendor
PublishPress
Product
PublishPress Authors
Provider severity
HIGH
Conflicts
0

CVE-2026-25308

Missing Authorization vulnerability in wp.insider Simple Membership simple-membership allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Membership: from n/a through <= 4.6.9.

PUBLISHED
Vendor
wp.insider
Product
Simple Membership
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25307

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows DOM-Based XSS.This issue affects XStore Core: from n/a through < 5.7.

PUBLISHED
Vendor
8theme
Product
XStore Core
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25306

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core et-core-plugin allows Reflected XSS.This issue affects XStore Core: from n/a through <= 5.6.4.

PUBLISHED
Vendor
8theme
Product
XStore Core
Provider severity
HIGH
Conflicts
0

CVE-2026-25305

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore xstore allows DOM-Based XSS.This issue affects XStore: from n/a through <= 9.6.4.

PUBLISHED
Vendor
8theme
Product
XStore
Provider severity
MEDIUM
Conflicts
0

CVE-2026-25304

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Jaroti jaroti allows Reflected XSS.This issue affects Jaroti: from n/a through < 1.4.8.

PUBLISHED
Vendor
skygroup
Product
Jaroti
Provider severity
HIGH
Conflicts
0

CVE-2026-2530

A weakness has been identified in Wavlink WL-WN579A3 up to 20210219. This affects the function AddMac of the file /cgi-bin/wireless.cgi. This manipulation of the argument macAddr causes command injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Wavlink
Product
WL-WN579A3
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25293

Buffer overflow due to incorrect authorization in PLC FW

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
CRITICAL
Conflicts
0

CVE-2026-2529

A security flaw has been discovered in Wavlink WL-WN579A3 up to 20210219. Affected by this issue is the function DeleteMac of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list results in command injection. The attack can be executed remotely. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Wavlink
Product
WL-WN579A3
Provider severity
MEDIUM
Conflicts
2

CVE-2026-2528

A vulnerability was identified in Wavlink WL-WN579A3 up to 20210219. Affected by this vulnerability is the function Delete_Mac_list of the file /cgi-bin/wireless.cgi. The manipulation of the argument delete_list leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Wavlink
Product
WL-WN579A3
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25277

Memory corruption while using Strongbox due to buffer overflow.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-25276

Memory corruption while using Strongbox due to missing bounds check.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-25271

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0

CVE-2026-2527

A vulnerability was determined in Wavlink WL-WN579A3 up to 20210219. Affected is an unknown function of the file /cgi-bin/login.cgi. Executing a manipulation of the argument key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Vendor
Wavlink
Product
WL-WN579A3
Provider severity
MEDIUM
Conflicts
2

CVE-2026-25268

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

PUBLISHED
Vendor
Qualcomm, Inc.
Product
Snapdragon
Provider severity
HIGH
Conflicts
0