Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

616 CVEs · published 2026-08-13 to 2026-08-13

CVEs (616, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 616 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-73349 MEDIUM 5.3 2026-08-13 Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.
CVE-2026-73346 HIGH 7.6 2026-08-13 Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
CVE-2026-73344 MEDIUM 5.9 2026-08-13 Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
CVE-2026-73340 MEDIUM 6.5 2026-08-13 Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.
CVE-2026-73188 NONE &mdash; 2026-08-13 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-13610.
CVE-2026-67991 HIGH 7.5 2026-08-13 crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on &hellip;
CVE-2026-67990 MEDIUM 5.4 2026-08-13 basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated&hellip;
CVE-2026-67986 HIGH 8.4 2026-08-13 amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method&hellip;
CVE-2026-66704 HIGH 7.2 2026-08-13 Unauthenticated Server Side Request Forgery (SSRF) in Gutenverse Companion <= 2.5.1 versions.
CVE-2026-66700 HIGH 7.1 2026-08-13 Unauthenticated Cross Site Scripting (XSS) in Smart Online Order for Clover <= 1.6.1 versions.
CVE-2026-66698 HIGH 7.1 2026-08-13 Unauthenticated Cross Site Scripting (XSS) in SureDash <= 1.10.1 versions.
CVE-2026-66697 HIGH 7.1 2026-08-13 Unauthenticated Cross Site Scripting (XSS) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.
CVE-2026-66693 MEDIUM 6.5 2026-08-13 Subscriber Broken Access Control in Motors <= 1.4.113 versions.
CVE-2026-66691 CRITICAL 9.8 2026-08-13 Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
CVE-2026-66689 MEDIUM 6.3 2026-08-13 Unauthenticated Broken Access Control in Anti Spam and list cleaner &#8211; AcyChecker <= 2.0.0 versions.
CVE-2026-66687 MEDIUM 6.5 2026-08-13 Customer Cross Site Scripting (XSS) in WpBookingly <= 1.3.2 versions.
CVE-2026-66661 HIGH 7.7 2026-08-13 Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.
CVE-2026-66660 MEDIUM 6.5 2026-08-13 Unauthenticated Broken Access Control in Contact Form 7 – PayPal & Stripe Add-on <= 2.5.1 versions.
CVE-2026-66658 HIGH 8.5 2026-08-13 Subscriber SQL Injection in Reviewer <= 3.14.2 versions.
CVE-2026-66657 HIGH 8.1 2026-08-13 Unauthenticated Local File Inclusion in Biagiotti Core <= 2.1.1 versions.
CVE-2026-66656 HIGH 8.1 2026-08-13 Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
CVE-2026-66655 HIGH 7.1 2026-08-13 Unauthenticated Cross Site Scripting (XSS) in MultiParcels Shipping For WooCommerce <= 1.30.36 versions.
CVE-2026-66654 MEDIUM 6.0 2026-08-13 Subscriber Server Side Request Forgery (SSRF) in Vehica Core <= 1.0.104 versions.
CVE-2026-66653 HIGH 8.1 2026-08-13 Unauthenticated Local File Inclusion in Barista <= 2.5.1 versions.
CVE-2026-66478 CRITICAL 9.3 2026-08-13 Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.