VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

16979 CVEsRSS

CVE-2026-91011Medium· 6.8
1w ago

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is s…

The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is s…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-91008Low· 3.7
1w ago

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attend…

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attend…

▾ SunlitEPSS 0.26%via NVD
CVE-2026-91010Medium· 4.3
1w ago

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather tha…

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather tha…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-91009Medium· 4.3
1w ago

The Active Woot Products Tables for WooCommerce

The Active Woot Products Tables for WooCommerce. 100% FREE  WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title …

▾ SunlitEPSS 0.14%via NVD
CVE-2026-90922Medium· 5.3
1w ago

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a pai…

The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a pai…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-91015Medium· 5.3
1w ago

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowi…

The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowi…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-90923Medium· 6.5
1w ago

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.

▾ SunlitEPSS 0.27%via NVD
CVE-2026-91019Medium· 4.9
1w ago

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe…

The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-50604Medium· 4.9
1w ago

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certai…

▾ SunlitAcer · Agent ServiceEPSS 0.21%via NVD
CVE-2026-24073High· 7.8
1w ago

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-24081High· 7.4
1w ago

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

▾ Twilightqualcomm · ar8035_firmwareEPSS 0.10%via NVD
CVE-2026-24075High· 7.8
1w ago

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

▾ Twilightqualcomm · wsa8845h_firmwareEPSS 0.06%via NVD
CVE-2026-24074High· 7.8
1w ago

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

▾ Twilightqualcomm · iqx5121_firmwareEPSS 0.07%via NVD
CVE-2026-25261Medium· 6.7
1w ago

Memory corruption while processing rear sensor IOCTL calls.

Memory corruption while processing rear sensor IOCTL calls.

▾ Sunlitqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2025-59607High· 7.8
1w ago

Memory Corruption when copying large input data exceeds normal allocation limits.

Memory Corruption when copying large input data exceeds normal allocation limits.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25281High· 7.4
1w ago

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.10%via NVD
CVE-2026-25275High· 7.5
1w ago

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

▾ Twilightqualcomm · q-7790_firmwareEPSS 0.19%via NVD
CVE-2026-25282High· 7.9
1w ago

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.06%via NVD
CVE-2026-25278High· 7.8
1w ago

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

▾ Twilightqualcomm · lemans_au_lgit_firmwareEPSS 0.05%via NVD
CVE-2026-25290High· 7.8
1w ago

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25284High· 7.3
1w ago

Information Disclosure when a pointer is reused after being deallocated.

Information Disclosure when a pointer is reused after being deallocated.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25283High· 8.8
1w ago

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25294High· 7.4
1w ago

Transient DOS while parsing frame during channel usage.

Transient DOS while parsing frame during channel usage.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.10%via NVD
CVE-2026-25280High· 7.8
1w ago

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

▾ Twilightqualcomm · wsa8845h_firmwareEPSS 0.07%via NVD
CVE-2026-87935High· 8.1
1w ago

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_…

▾ Twilightichurakov · Paid DownloadsEPSS 0.91%via NVD
CVE-2026-87796Critical· 9.8PoC
1w ago

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked uplo…

▾ Abyssalsh1zen · Multi Uploader for Gravity FormsEPSS 1.1%via NVD
CVE-2026-86311Medium· 6.4
1w ago

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…

▾ Sunlit10web · Photo Gallery by 10Web – Mobile-Friendly Image GalleryEPSS 0.26%via NVD
CVE-2026-92839Medium· 4.3
1w ago

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

▾ SunlitCanva · CanvaEPSS 0.28%via NVD
CVE-2026-50603Medium· 4.9
1w ago

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstance…

▾ SunlitAcer · Agent ServiceEPSS 0.10%via NVD
CVE-2026-89064Medium· 5.3
1w ago

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin…

▾ Sunlitservmask · All-in-One WP Migration and BackupEPSS 0.50%via NVD
CVEs tagged “cve.org” — page 200 · VulnSea