VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

26610 CVEsRSS

CVE-2026-74002Medium· 5.3
1w ago

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.

▾ Sunlitwpdevelop · bookingEPSS 0.29%via NVD
CVE-2026-74000Medium· 5.3
1w ago

Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.

Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.

▾ Sunlitwp.insider · simple-membershipEPSS 0.29%via NVD
CVE-2026-73999Medium· 5.4
1w ago

Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.

Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.

▾ SunlitGora Tech · cookedEPSS 0.29%via NVD
CVE-2026-71568Medium· 5.3
1w ago

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.

In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.

▾ Sunlitopenshift-metal3 · bmctestEPSS 0.23%via NVD
CVE-2026-66676Medium· 5.3
1w ago

Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.

Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.

▾ SunlitMatrixAddons · easy-invoiceEPSS 0.31%via NVD
CVE-2026-66631High· 7.6
1w ago

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

▾ TwilightMoreconvert Team · smart-wishlist-for-more-convertEPSS 0.38%via NVD
CVE-2026-66630High· 7.6
1w ago

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

▾ TwilightPublishPress · organize-seriesEPSS 0.38%via NVD
CVE-2026-66628High· 7.6
1w ago

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

▾ TwilightWP Lab · wp-lister-for-ebayEPSS 0.38%via NVD
CVE-2026-66626High· 7.6
1w ago

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

▾ TwilightSonal S Sinha · skt-addons-for-elementorEPSS 0.38%via NVD
CVE-2026-66625High· 7.6
1w ago

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

▾ TwilightWCVendors · wc-vendorsEPSS 0.38%via NVD
CVE-2026-66624High· 7.6
1w ago

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

▾ TwilightLudwig You · wpmastertoolkitEPSS 0.38%via NVD
CVE-2026-66619High· 7.6
1w ago

Administrator SQL Injection in Newsletters <= 4.18 versions.

Administrator SQL Injection in Newsletters <= 4.18 versions.

▾ TwilightTribulant Software · newsletters-liteEPSS 0.38%via NVD
CVE-2026-66618High· 7.6
1w ago

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

▾ TwilightFlipper Code · wp-google-map-pluginEPSS 0.38%via NVD
CVE-2026-66617Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.

▾ SunlitPublishPress · organize-seriesEPSS 0.22%via NVD
CVE-2026-66608Medium· 6.4
1w ago

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.

▾ SunlitUnlimited Elements · unlimited-elements-for-elementorEPSS 0.23%via NVD
CVE-2026-66580High· 8.5
1w ago

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

▾ TwilightRexTheme · best-woocommerce-feedEPSS 0.36%via NVD
CVE-2026-66579Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetElements For ElementorEPSS 0.22%via NVD
CVE-2026-66578Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.

Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.

▾ SunlitProperty Hive · propertyhiveEPSS 0.22%via NVD
CVE-2026-66577Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetSearchEPSS 0.22%via NVD
CVE-2026-66576Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.

Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetBlocks For ElementorEPSS 0.22%via NVD
CVE-2026-66575Medium· 5.3
1w ago

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

▾ SunlitKingAddons.com · king-addonsEPSS 0.29%via NVD
CVE-2026-66574Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

▾ Sunlitbdthemes · bdthemes-element-pack-liteEPSS 0.22%via NVD
CVE-2026-66573Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetTabsEPSS 0.22%via NVD
CVE-2026-66572Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetBlogEPSS 0.22%via NVD
CVE-2026-66571High· 7.1
1w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

▾ TwilightGabe Livan · wp-asset-clean-upEPSS 0.13%via NVD
CVE-2026-62108Critical· 9.8
1w ago

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

▾ MidnightminiOrange · headless-single-sign-onEPSS 0.61%via NVD
CVE-2026-62104Critical· 10.0
1w ago

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

▾ Midnightsuperweby · migratico-liteEPSS 0.86%via NVD
CVE-2026-62101Critical· 9.8
1w ago

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

▾ MidnightChris Åkerfeldt Wendel · eduadmin-bookingEPSS 0.61%via NVD
CVE-2026-14850High· 8.8
1w ago

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users…

▾ TwilightMobiAPParc · MobiAPParcEPSS 0.29%via NVD
CVE-2026-82723Low· 1.8
1w ago

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.18%via NVD
CVEs tagged “nvd” — page 187 · VulnSea