Export limit exceeded: 11515 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (11515 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-12349 2026-06-30 5.3 Medium
The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including, 1.1.1. This is due to missing authorization and capability checks on the add_custom_sidebar() and remove_custom_sidebar() AJAX handlers, both of which are exposed through wp_ajax_nopriv_* hooks and write directly to the octagon_custom_sidebar option via update_option(). This makes it possible for unauthenticated attackers to create arbitrary custom widget areas or delete existing custom sidebars, which can cause widgets assigned to those areas to silently lose their registration and stop rendering.
CVE-2026-57520 1 Bitwarden 1 Server 2026-06-30 7.1 High
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint. Attackers can supply Admin organization-user IDs in a bulk DELETE request to bypass the guard enforced on the single-user removal path, effectively removing one or more Admin accounts from an organization.
CVE-2026-56768 1 Haiwen 1 Seahub 2026-06-30 8.8 High
Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory trees.
CVE-2026-57498 1 Coollabsio 1 Coolify 2026-06-30 9.6 Critical
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. However, multiple Livewire web UI components accept server_id and destination_uuid from URL query parameters without any team ownership validation, allowing cross-team resource deployment. This vulnerability is fixed in 4.0.0-beta.474.
CVE-2024-10306 1 Redhat 3 Enterprise Linux, Jboss Core Services, Rhel Eus 2026-06-29 5.4 Medium
A vulnerability was found in mod_proxy_cluster. The issue is that the <Directory> directive should be replaced by the <Location> directive as the former does not restrict IP/host access as `Require ip IP_ADDRESS` would suggest. This means that anyone with access to the host might send MCMP requests that may result in adding/removing/updating nodes for the balancing. However, this host should not be accessible to the public network as it does not serve the general traffic.
CVE-2026-57340 2 Shoheitanaka, Wordpress 2 Japanized For Woocommerce, Wordpress 2026-06-29 6.5 Medium
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
CVE-2026-57327 2 Mainwp, Wordpress 2 Mainwp, Wordpress 2026-06-29 6.3 Medium
Subscriber Broken Access Control in MainWP <= 6.1.1 versions.
CVE-2026-57332 2 Wordpress, Wpswings 2 Wordpress, Wallet System For Woocommerce 2026-06-29 7.1 High
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
CVE-2026-57334 2 Wedevs, Wordpress 2 Wp User Frontend, Wordpress 2026-06-29 6.5 Medium
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
CVE-2025-2515 1 Eclipse 1 Bluechi 2026-06-29 7.2 High
A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node. This issue can lead to privilege escalation, unauthorized service execution, and potential system compromise.
CVE-2025-63041 2 Codeamp, Wordpress 2 Forget About Shortcode Buttons, Wordpress 2026-06-29 5.4 Medium
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
CVE-2025-63078 2 Jetmonsters, Wordpress 2 Restaurant Menu By Motopress, Wordpress 2026-06-29 4.3 Medium
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2025-63079 2 Bdthemes, Wordpress 2 Live Copy Paste For Elementor, Wordpress 2026-06-29 4.3 Medium
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
CVE-2025-64636 2 Rhewlif, Wordpress 2 Donation Thermometer, Wordpress 2026-06-29 5.3 Medium
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
CVE-2026-54835 2 Rustaurius, Wordpress 2 Five Star Restaurant Menu, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.
CVE-2026-54837 2 Syed Balkhi, Wordpress 2 Intranet & Private Site – All-in-one Intranet, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.
CVE-2026-54846 2 Akosglys, Wordpress 2 Syncee Premium Dropshipping & Wholesale, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.
CVE-2026-56025 2 Paymob, Wordpress 2 Paymob For Woocommerce, Wordpress 2026-06-29 7.5 High
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
CVE-2026-56038 2 Frisbii, Wordpress 2 Frisbii Pay, Wordpress 2026-06-29 8.8 High
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
CVE-2026-56063 2 Bplugins, Wordpress 2 Mailchimp Block, Wordpress 2026-06-29 8.3 High
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.