Total
8714 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-65435 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions. | |||||
| CVE-2026-65433 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg <= 1.5.1 versions. | |||||
| CVE-2026-59529 | 2026-07-27 | N/A | 7.5 HIGH | ||
| Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 versions. | |||||
| CVE-2026-59530 | 2026-07-27 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions. | |||||
| CVE-2026-66442 | 2026-07-27 | N/A | 5.4 MEDIUM | ||
| Subscriber Broken Access Control in YayPricing <= 3.5.6 versions. | |||||
| CVE-2026-59557 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions. | |||||
| CVE-2026-59536 | 2026-07-27 | N/A | 7.5 HIGH | ||
| Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions. | |||||
| CVE-2026-59560 | 2026-07-27 | N/A | 6.5 MEDIUM | ||
| Subscriber Broken Access Control in FundEngine <= 1.7.8 versions. | |||||
| CVE-2026-65567 | 2026-07-27 | N/A | 5.3 MEDIUM | ||
| Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions. | |||||
| CVE-2026-0814 | 2026-07-25 | N/A | 4.3 MEDIUM | ||
| The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'vsz_cf7_export_to_excel' function in all versions up to, and including, 2.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export form submissions to excel file. | |||||
| CVE-2025-15634 | 1 Hcltech | 21 Bigfix Webui Api, Bigfix Webui Application Administration, Bigfix Webui Cmep and 18 more | 2026-07-25 | N/A | 4.3 MEDIUM |
| A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized page. | |||||
| CVE-2025-15565 | 2026-07-25 | N/A | 5.3 MEDIUM | ||
| The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization checks on the redirect function in all versions up to, and including, 8.3.0. This makes it possible for unauthenticated attackers to mark pending WooCommerce orders as paid/completed. | |||||
| CVE-2026-3208 | 2026-07-25 | N/A | 5.3 MEDIUM | ||
| The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all versions up to, and including, 8.7.11. This makes it possible for unauthenticated attackers to retrieve PIX payment QR code images for arbitrary orders. PIX QR codes contain sensitive merchant information including PIX keys (which may be CPF/CNPJ personal identifiers), transaction amounts, merchant name and city, and MercadoPago transaction references. | |||||
| CVE-2025-9484 | 1 Gitlab | 1 Gitlab | 2026-07-25 | N/A | 4.3 MEDIUM |
| GitLab has remediated an issue in GitLab EE affecting all versions from 16.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that under certain circumstances could have allowed an authenticated user to have access to other users' email addresses via certain GraphQL queries. | |||||
| CVE-2021-47932 | 2026-07-25 | N/A | 9.8 CRITICAL | ||
| WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to administrator to gain full administrative access without authentication. | |||||
| CVE-2026-58275 | 2026-07-25 | N/A | 10.0 CRITICAL | ||
| Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | |||||
| CVE-2026-2263 | 2026-07-24 | N/A | 5.3 MEDIUM | ||
| The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This makes it possible for unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are never displayed to users, thereby manipulating marketing analytics and conversion statistics. | |||||
| CVE-2026-33420 | 1 Dani-garcia | 1 Vaultwarden | 2026-07-24 | N/A | 5.3 MEDIUM |
| Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exists on the sibling get_org_collections endpoint. This allows any Manager-role user with accessAll=False and no collection assignments to retrieve the names, UUIDs, user-to-collection mappings, and group-to-collection mappings for all collections in the organization. This issue has been fixed in version 1.35.5. | |||||
| CVE-2026-33229 | 1 Xwiki | 1 Xwiki | 2026-07-24 | N/A | 9.8 CRITICAL |
| XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scripting API and execute, e.g., arbitrary Python scripts, allowing full access to the XWiki instance and thereby compromising the confidentiality, integrity and availability of the whole instance. Note that script right already constitutes a high level of access that we don't recommend giving to untrusted users. This vulnerability is fixed in 17.4.8 and 17.10.1. | |||||
| CVE-2026-11354 | 2026-07-24 | N/A | 5.3 MEDIUM | ||
| The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing record-access link to an attacker-controlled email address, granting full read and edit access to the victim's stored personally identifiable information including names, email addresses, phone numbers, and any other fields collected in the participant database. An attacker can harvest a valid nonce with a plain unauthenticated GET request to any page rendering the public signup or record form, then POST action=update with an arbitrary id value to overwrite any record; chaining a subsequent action=retrieve then delivers the private-access link to the attacker-controlled mailbox. | |||||
