| CVE-2026-64635 | Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service... | medium | |
| CVE-2026-59328 | Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native... | medium | |
| CVE-2026-59327 | Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote... | medium | |
| CVE-2026-59326 | The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy... | low | |
| CVE-2026-58066 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8,... | critical | |
| CVE-2026-58046 | Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged... | critical | |
| CVE-2026-47882 | When enabling Spring Boot DevTools support for a remote application target (for example a Docker... | high | |
| CVE-2026-47873 | The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of... | high | |
| CVE-2026-47858 | Starting Spring Boot applications in the Spring Tools with the live information mode enabled... | high | |
| CVE-2026-15382 | The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a... | critical | |
| CVE-2026-15257 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership... | critical | |
| CVE-2026-15255 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time... | critical | |
| CVE-2026-15252 | The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check... | critical | |
| CVE-2026-15250 | The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking... | critical | |
| CVE-2026-15240 | The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user... | critical | |
| CVE-2026-15235 | The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check... | No Score | |
| CVE-2026-15153 | The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search... | critical | |
| CVE-2026-15054 | The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on... | medium | |
| CVE-2026-14923 | The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page... | medium | |
| CVE-2026-14602 | The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing... | critical | |
| CVE-2026-14592 | The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any... | critical | |
| CVE-2026-14318 | The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting... | critical | |
| CVE-2026-14310 | The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to... | critical | |
| CVE-2026-14305 | The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one... | critical | |
| CVE-2026-14239 | The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom... | critical | |
| CVE-2026-14231 | The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its... | critical | |
| CVE-2026-14226 | The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability... | high | |
| CVE-2026-14223 | The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability... | critical | |
| CVE-2026-14222 | The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce... | critical | |
| CVE-2026-14221 | The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in... | critical | |
| CVE-2026-14207 | The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a... | medium | |
| CVE-2026-14188 | The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability... | critical | |
| CVE-2026-13395 | The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not... | high | |
| CVE-2026-13345 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization... | critical | |
| CVE-2026-13344 | The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag... | high | |
| CVE-2026-13330 | The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG... | high | |
| CVE-2026-13178 | The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and... | high | |
| CVE-2026-13145 | The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its... | critical | |
| CVE-2026-13143 | The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment... | high | |
| CVE-2026-12687 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous... | high | |
| CVE-2026-12500 | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an... | medium | |
| CVE-2026-11881 | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form... | critical | |
| CVE-2026-11870 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP... | critical | |
| CVE-2026-11867 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability... | critical | |
| CVE-2026-11782 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation... | medium | |
| CVE-2026-67248 | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this issue to cause denial of service of the affected CGI process. Further impact may be possible depending on exploitability and runtime protections. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81. | high | 2026-07-30 |
| CVE-2026-67247 | A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM log database file. An authenticated attacker can exploit this issue to cause the affected component to access an unintended filesystem path or log database file. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81. | high | 2026-07-30 |
| CVE-2026-67246 | A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit this issue to access or manipulate files outside the intended wallpaper directory, subject to user permissions and filesystem restrictions. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81. | medium | 2026-07-30 |
| CVE-2026-67245 | A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated attacker can exploit this issue to write an uploaded certificate file outside the intended VPN certificate directory, subject to process privileges and filesystem permissions. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81. | high | 2026-07-30 |
| CVE-2026-16610 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html without any sanitization or identifier validation. This makes it possible for unauthenticated attackers to execute code on the server. This requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID needed to reach the vulnerable save handler are emitted to unauthenticated visitors by that shortcode. | critical | 2026-07-30 |