Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 226–250 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-16296 MEDIUM Patched 4.7 2026-08-04 The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect handler, passing a decoded request URI to an unsafe…
CVE-2026-16295 MEDIUM Patched 4.3 2026-08-04 The Clearfy Cache WordPress plugin before 2.4.3 does not perform a capability check in one of its admin-page dispatch paths, allowing any authenticated user such as a Subs…
CVE-2026-16293 MEDIUM Patched 6.8 2026-08-04 The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which could allow users with…
CVE-2026-16070 LOW Patched 2.7 2026-08-04 The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request p…
CVE-2026-16069 MEDIUM Patched 6.8 2026-08-04 The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX actions before storing them a…
CVE-2026-16068 LOW Patched 3.5 2026-08-04 The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data before outputting it…
CVE-2026-16056 MEDIUM Patched 4.3 2026-08-04 The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscribe…
CVE-2026-16035 MEDIUM Patched 4.3 2026-08-04 The miniOrange 2FA WordPress plugin before 6.2.7 does not restrict who can trigger its second-factor configuration OTP send, nor bind the OTP recipient to the enrolling us…
CVE-2026-15958 CRITICAL Patched 9.3 2026-08-04 The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers …
CVE-2026-15233 MEDIUM Patched 4.8 2026-08-04 The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML attributes on an administrative listing screen, allowi…
CVE-2026-14939 MEDIUM Patched 6.8 2026-08-04 The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing users with Contributor-l…
CVE-2026-14872 MEDIUM Patched 6.8 2026-08-04 The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement…
CVE-2026-14848 MEDIUM Patched 5.4 2026-08-04 The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to th…
CVE-2026-14824 MEDIUM Patched 4.8 2026-08-04 The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, allowing …
CVE-2026-14816 MEDIUM Patched 6.5 2026-08-04 The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices…
CVE-2026-12698 MEDIUM Patched 4.3 2026-08-04 The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with a subscriber-leve…
CVE-2026-11366 LOW Patched 3.7 2026-08-04 The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPres…
CVE-2026-10526 MEDIUM Patched 5.8 2026-08-04 The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenti…
CVE-2026-68744 LOW 3.3 2026-08-04 A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet wh…
CVE-2026-18739 LOW 2.5 2026-08-04 A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through …
CVE-2026-18569 LOW 3.7 2026-08-04 A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component handles authenticatio…
CVE-2026-16881 NONE — 2026-08-04 A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally …
CVE-2026-42169 HIGH 7.3 2026-08-04 A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixe…
CVE-2026-18723 MEDIUM 6.3 2026-08-04 A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the…
CVE-2026-18722 MEDIUM 6.3 2026-08-04 A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-surve…