Search
100 CVEs · published 2026-08-30 to 2026-08-30
CVEs (100)
Showing 1–25 of 100
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14307 | NONE | Patched | — | 2026-08-30 | The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML… |
| CVE-2026-14835 | NONE | — | 2026-08-30 | The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post me… | |
| CVE-2026-15980 | CRITICAL | 9.8 | 2026-08-30 | The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_li… | |
| CVE-2026-19722 | NONE | Patched | — | 2026-08-30 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, all… |
| CVE-2026-56713 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-56715 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-56716 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-56718 | HIGH | 7.5 | 2026-08-30 | AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to… | |
| CVE-2026-64839 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-64840 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-64841 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-64842 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-64843 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-64844 | NONE | — | 2026-08-30 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-75759 | NONE | Patched | — | 2026-08-30 | Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token … |
| CVE-2026-75847 | NONE | Patched | — | 2026-08-30 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the… |
| CVE-2026-76585 | NONE | Patched | — | 2026-08-30 | The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which c… |
| CVE-2026-77454 | NONE | Patched | — | 2026-08-30 | Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that decl… |
| CVE-2026-77831 | NONE | Patched | — | 2026-08-30 | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update act… |
| CVE-2026-77846 | NONE | Patched | — | 2026-08-30 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse int… |
| CVE-2026-77970 | NONE | Patched | — | 2026-08-30 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sen… |
| CVE-2026-78038 | NONE | Patched | — | 2026-08-30 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of A… |
| CVE-2026-78228 | NONE | Patched | — | 2026-08-30 | Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and … |
| CVE-2026-78364 | NONE | Patched | — | 2026-08-30 | The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allo… |
| CVE-2026-78691 | NONE | Patched | — | 2026-08-30 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_w… |