#
412 Vulnerabilities
2026-07-26
CVE-2026-9729
CVE-2026-9729 - Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter
General
3.1 (MEDIUM)
2026-07-26
CVE-2026-9635
CVE-2026-9635 - WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute
General
3.1 (MEDIUM)
2026-07-26
CVE-2026-9713
CVE-2026-9713 - Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload
php
3.1 (HIGH)
2026-07-26
CVE-2026-12082
CVE-2026-12082 - Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
General
3.1 (HIGH)
2026-07-26
CVE-2026-14291
CVE-2026-14291 - Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa
General
3.1 (HIGH)
2026-07-26
CVE-2026-59676
CVE-2026-59676 - Local File Deletion Attack Vector in rm_rf() in seunshare
General
2026-07-26
CVE-2026-9066
CVE-2026-9066 - WP Compress < 7.10.04 - Reflected XSS via test_zone
General
2026-07-26
CVE-2026-9577
CVE-2026-9577 - Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter
General
2026-07-26
CVE-2026-63226
CVE-2026-63226 - Ricoh Multifunction Printers SSH Port Forwarding Arbitrary Connection Vulnerability
printers
4.0 (MEDIUM)
2026-07-26
CVE-2026-7534
CVE-2026-7534 - SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter
General
3.1 (HIGH)
2026-07-26
CVE-2026-7232
CVE-2026-7232 - FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters
General
3.1 (HIGH)
2026-07-26
CVE-2026-64600
CVE-2026-64600 - xfs: resample the data fork mapping after cycling ILOCK
General
2026-07-26
CVE-2026-6390
CVE-2026-6390 - Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.
General
3.1 (MEDIUM)
2026-07-26
CVE-2026-7120
CVE-2026-7120 - @fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths
General
2026-07-26
CVE-2026-15074
CVE-2026-15074 - @fastify/static vulnerable to route guard bypass via path traversal
General
3.1 (HIGH)
2026-07-26
CVE-2026-16631
CVE-2026-16631 - publint package-manager pack.js child_process.exec os command injection
General
3.1 (MEDIUM)
2026-07-26
CVE-2026-16632
CVE-2026-16632 - boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation
General
2.0 (HIGH)
2026-07-26
CVE-2026-16653
CVE-2026-16653 - boazsegev facil.io Public Folder http.c http_sendfile2 path traversal
General
4.0 (MEDIUM)
2026-07-26
CVE-2026-16630
CVE-2026-16630 - syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
java
3.1 (MEDIUM)
2026-07-26
CVE-2026-38763
CVE-2026-38763 - Protegent 360 Denial of Service Vulnerability
General
3.1 (MEDIUM)
2026-07-26
CVE-2026-38765
CVE-2026-38765 - Protegent 360 Kernel Driver Privilege Escalation
General
3.1 (HIGH)
2026-07-26
CVE-2026-38766
CVE-2026-38766 - Protegent 360 Local Privilege Escalation
General
3.1 (HIGH)
2026-07-26
CVE-2026-60366
CVE-2026-60366 - Vulnerability in the Oracle Platform Security for
General
3.1 (CRITICAL)
2026-07-26
CVE-2026-60367
CVE-2026-60367 - Vulnerability in the Oracle Platform Security for
General
3.1 (CRITICAL)
No matching CVEs found with current filter options.