Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

478 CVEs · Critical severity

CVEs (478)

Showing 26–50 of 478

CVE ID Severity Patch CVSS Published Description
CVE-2026-61949 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in Bookly <= 27.7 versions.
CVE-2026-61948 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.
CVE-2026-59555 CRITICAL 10.0 2026-07-23 Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
CVE-2026-59544 CRITICAL 9.8 2026-07-23 Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.
CVE-2026-59543 CRITICAL 9.9 2026-07-23 Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVE-2026-59540 CRITICAL 9.8 2026-07-23 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.
CVE-2026-59526 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.
CVE-2026-59525 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.
CVE-2026-59514 CRITICAL 9.3 2026-07-23 Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.
CVE-2026-57784 CRITICAL 9.6 2026-07-23 Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
CVE-2026-27064 CRITICAL 9.1 2026-07-23 Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-15015 CRITICAL 9.8 2026-07-23 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugi&hellip;
CVE-2026-15011 CRITICAL 9.8 2026-07-23 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due &hellip;
CVE-2026-14282 CRITICAL 9.8 2026-07-23 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in&hellip;
CVE-2026-16723 CRITICAL 9.0 2026-07-23 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au&hellip;
CVE-2026-60372 CRITICAL 9.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-60369 CRITICAL 9.9 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-60367 CRITICAL 9.8 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-60366 CRITICAL 10.0 2026-07-22 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected a&hellip;
CVE-2026-46738 CRITICAL 9.1 2026-07-22 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote ac&hellip;
CVE-2026-40712 CRITICAL 9.1 2026-07-22 Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote ac&hellip;
CVE-2026-16606 CRITICAL 9.8 2026-07-22 A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-aut&hellip;
CVE-2026-2395 CRITICAL 9.8 2026-07-22 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL &hellip;
CVE-2026-62144 CRITICAL 9.1 2026-07-22 An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administ&hellip;
CVE-2026-16232 CRITICAL Patched 9.1 2026-07-22 An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use &hellip;