Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-64635Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service...
medium
CVE-2026-59328Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native...
medium
CVE-2026-59327Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote...
medium
CVE-2026-59326The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy...
low
CVE-2026-58066Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8,...
critical
CVE-2026-58046Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged...
critical
CVE-2026-47882When enabling Spring Boot DevTools support for a remote application target (for example a Docker...
high
CVE-2026-47873The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of...
high
CVE-2026-47858Starting Spring Boot applications in the Spring Tools with the live information mode enabled...
high
CVE-2026-15382The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a...
critical
CVE-2026-15257The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership...
critical
CVE-2026-15255The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time...
critical
CVE-2026-15252The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check...
critical
CVE-2026-15250The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking...
critical
CVE-2026-15240The Customer Switching WordPress plugin before 2.1.3 does not securely bind an active user...
critical
CVE-2026-15235The MotoPress Hotel Booking WordPress plugin before 6.0.4 does not perform a capability check...
No Score
CVE-2026-15153The WP Hotel Booking WordPress plugin before 2.3.2 does not sanitise and escape a search...
critical
CVE-2026-15054The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on...
medium
CVE-2026-14923The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page...
medium
CVE-2026-14602The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing...
critical
CVE-2026-14592The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any...
critical
CVE-2026-14318The GiveWP WordPress plugin before 4.16.3 does not escape a donation-form template setting...
critical
CVE-2026-14310The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to...
critical
CVE-2026-14305The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one...
critical
CVE-2026-14239The tourmaster WordPress plugin before 5.4.8 does not perform a nonce check when storing a custom...
critical
CVE-2026-14231The LifterLMS WordPress plugin before 10.0.10 does not perform a capability check in one of its...
critical
CVE-2026-14226The Easy Appointments WordPress plugin through 3.12.26 does not require a sufficient capability...
high
CVE-2026-14223The Easy Appointments WordPress plugin through 3.12.26 does not verify ownership or capability...
critical
CVE-2026-14222The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce...
critical
CVE-2026-14221The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in...
critical
CVE-2026-14207The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a...
medium
CVE-2026-14188The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability...
critical
CVE-2026-13395The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not...
high
CVE-2026-13345The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization...
critical
CVE-2026-13344The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag...
high
CVE-2026-13330The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG...
high
CVE-2026-13178The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and...
high
CVE-2026-13145The WP Travel WordPress plugin before 11.8.1 does not verify that the booking requested on its...
critical
CVE-2026-13143The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment...
high
CVE-2026-12687The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous...
high
CVE-2026-12500The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an...
medium
CVE-2026-11881The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form...
critical
CVE-2026-11870The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP...
critical
CVE-2026-11867The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability...
critical
CVE-2026-11782The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation...
medium
CVE-2026-67248A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because user-controlled input is not properly validated before being decoded and copied into a fixed-size stack buffer. An authenticated attacker can exploit this issue to cause denial of service of the affected CGI process. Further impact may be possible depending on exploitability and runtime protections. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
high
2026-07-30
CVE-2026-67247A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not sufficiently validated before being used to construct the path of an IHM log database file. An authenticated attacker can exploit this issue to cause the affected component to access an unintended filesystem path or log database file. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
high
2026-07-30
CVE-2026-67246A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is not sufficiently validated before being used for file access. An authenticated attacker can exploit this issue to access or manipulate files outside the intended wallpaper directory, subject to user permissions and filesystem restrictions. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
medium
2026-07-30
CVE-2026-67245A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is not sufficiently validated before being used to construct the upload destination path. An authenticated attacker can exploit this issue to write an uploaded certificate file outside the intended VPN certificate directory, subject to process privileges and filesystem permissions. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
high
2026-07-30
CVE-2026-16610The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no authentication check, CAPTCHA validation is bypassable by omitting an attacker-supplied key, and repeater row keys from cfgroup[input] are stored verbatim and later spliced into an eval() call in recursive_html without any sanitization or identifier validation. This makes it possible for unauthenticated attackers to execute code on the server. This requires the [post_cf_form] shortcode to be present on at least one publicly accessible page, as the nonce and session ID needed to reach the vulnerable save handler are emitted to unauthenticated visitors by that shortcode.
critical
2026-07-30