VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15636 CVEsRSS

CVE-2026-84098Medium· 6.5
5d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and …

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated attackers with Subscriber-level access and …

▾ SunlitEPSS 0.21%via NVD
CVE-2026-84046Medium· 5.0
5d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the s…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users with the subscriber role and above to make the s…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-84027Medium· 4.3
5d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to crea…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, allowing users with the subscriber role and above to crea…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-84026Medium· 5.3
5d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' p…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, allowing unauthenticated attackers to read registered users' p…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-83555Medium· 5.3
5d ago

The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-conf…

The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-conf…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-82843Critical· 9.0
5d ago

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever u…

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever u…

▾ MidnightEPSS 0.19%via NVD
CVE-2026-81339Medium· 4.3
5d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other stude…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated user with a minimal (subscriber) role to read other stude…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-81338Medium· 4.6
5d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts …

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it to other users, allowing users with subscriber-level accounts …

▾ SunlitEPSS 0.09%via NVD
CVE-2026-80342Medium· 6.5
5d ago

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, …

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the WooCommerce order being paid unless that PayPal order has already been completed, …

▾ SunlitEPSS 0.20%via NVD
CVE-2026-77766Medium· 4.3
5d ago

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read ev…

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting user, allowing users with a subscriber-level account to read ev…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-77765Medium· 5.3
5d ago

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbit…

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway charge, allowing unauthenticated users to pay an arbit…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-75799Critical· 9.0
5d ago

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE …

The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly accessible directory, allowing unauthenticated attackers to write arbitrary PHP files on the server and achieve RCE …

▾ MidnightEPSS 0.26%via NVD
CVE-2026-19438High· 7.5
5d ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. This issue affects Mint Workbench I: through 5876.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. This issue affects Mint Workbench I: through 5876.

▾ TwilightABB · Mint Workbench IEPSS 0.27%via NVD
CVE-2026-18365Medium· 4.3
5d ago

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user,…

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level account to disclose the display name and email address of every registered user,…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-18364Medium· 4.3
5d ago

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level account to modify the zportals WordPress plugin before 6.4.2's stored integr…

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on several of its AJAX actions, allowing users with a subscriber-level account to modify the zportals WordPress plugin before 6.4.2's stored integr…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-16264Medium· 6.5
5d ago

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subsc…

The Newsletters WordPress plugin before 4.18.1 does not perform an ownership check on some of its subscriber management actions, and issues a management session to unauthenticated visitors on request, allowing attackers to read any subsc…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-14321High· 8.2
5d ago

The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting,…

The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting,…

▾ TwilightEPSS 0.26%via NVD
CVE-2025-15696Medium· 6.8
5d ago

The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts tha…

The Real3D Flipbook WordPress plugin before 5.4 does not sanitize or escape several flipbook editor fields before rendering them back in the admin editor, allowing users with the Author role and above to inject arbitrary web scripts tha…

▾ SunlitEPSS 0.29%via NVD
CVE-2022-4997High· 8.6
5d ago

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including pass…

The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including pass…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-96258Medium· 4.3PoC
5d ago

A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722

A vulnerability has been found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. This affects an unknown part of the file /forgotpasswd.html of the component Public Password Reset Endpoint. The manipulation of the argum…

▾ TwilightonSite internet GmbH · Auktion NG AuktionssoftwareEPSS 0.26%via NVD
CVE-2026-95930Medium· 6.3PoC
5d ago

A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6

A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint lea…

▾ TwilightiFlytek · astron-agentEPSS 0.30%via NVD
CVE-2026-95957Medium· 4.3PoC
5d ago

A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0

A vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the arg…

▾ TwilightSourceCodester · Smart Attendance System with QR Code ScannerEPSS 0.27%via NVD
CVE-2026-91777High· 7.5PoC
5d ago

Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID

Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferr…

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-databindEPSS 0.45%via NVD
CVE-2026-91776High· 7.5PoC
5d ago

TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID

TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use =…

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-databindEPSS 0.45%via NVD
CVE-2026-95958Low· 3.3
5d ago

A security flaw has been discovered in JusticeRage Manalyze 1.0.0

A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of the file manape/pe.cpp of the component PE Parser. Performing a manipulation of the argument BlockSize results in integ…

▾ SunlitJusticeRage · ManalyzeEPSS 0.11%via NVD
CVE-2026-95929Medium· 6.3
5d ago

A weakness has been identified in iFlytek astron-agent up to 1.0.7

A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing…

▾ SunlitiFlytek · astron-agentEPSS 0.23%via NVD
CVE-2026-96257Critical· 10.0PoC
5d ago

A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4

A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack…

▾ AbyssalFast · FAC1203R Gigabit EditionEPSS 0.58%via NVD
CVE-2026-89425High· 7.5PoC
5d ago

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three …

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-coreEPSS 0.49%via NVD
CVE-2026-95926High· 7.3PoC
5d ago

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of …

▾ MidnightSourceCodester · Online Reviewer Management SystemEPSS 0.26%via NVD
CVE-2026-95928Medium· 5.5PoC
5d ago

A security flaw has been discovered in recommenders-team recommenders up to 1.2.1

A security flaw has been discovered in recommenders-team recommenders up to 1.2.1. This impacts the function pickle.load of the file recommenders/models/newsrec/io/mind_iterator.py of the component Dict Loading. Performing a manipulation…

▾ Twilightrecommenders-team · recommendersEPSS 0.19%via NVD
CVEs tagged “cve.org” — page 74 · VulnSea