CVE-2026-1233 · 2026-07-21 · auto
The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing hardcoded MySQL dat…
CVE-2026-3445 · 2026-07-21 · auto
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to…
CVE-2026-4896 · 2026-07-21 · auto
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.25 via mul…
CVE-2026-4350 · 2026-07-21 · auto
The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method processing the `$_GET['de…
CVE-2026-9757 · 2026-07-21 · auto
The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters are read from $_SERVER['QUERY_STRING'] via parse_s…
CVE-2026-42941 · 2026-07-21 · auto
The Danelec MacGregor Voyage Data Recorder
device includes a default username and password, with no enforced password change.
CVE-2026-1771 · 2026-07-21 · auto
The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up to, and including, 8.14.0 This is due to an incorrect conditional …
CVE-2016-15058 · 2026-07-21 · auto
Hirschmann HiLCOS Classic Platform switches Classic L2E, L2P, L3E, L3P versions prior to 09.0.06 and Classic L2B prior to 05.3.07 contain a credential exposure vulnerability where user passwords are synchronized with SNM…
CVE-2026-48373 · 2026-07-21 · auto
Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi…
CVE-2026-63304 · 2026-07-21 · auto
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without …
CVE-2026-4808 · 2026-07-20 · auto
The Gerador de Certificados – DevApps plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the moveUploadedFile() function in all versions up to, and including, 1.3.6. This …
CVE-2024-30104 · 2026-07-20 · auto
Microsoft Office Remote Code Execution Vulnerability
CVE-2024-30103 · 2026-07-20 · auto
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-30101 · 2026-07-20 · auto
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-33216 · 2026-07-20 · auto
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classif…
CVE-2026-13042 · 2026-07-18 · auto
The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes …
CVE-2026-12753 · 2026-07-18 · auto
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficien…
CVE-2026-7543 · 2026-07-17 · auto
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes i…
CVE-2026-11961 · 2026-07-17 · auto
The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that…
CVE-2026-11575 · 2026-07-17 · auto
The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through…
CVE-2026-13765 · 2026-07-17 · auto
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes i…
CVE-2026-13352 · 2026-07-17 · auto
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, …
CVE-2026-15395 · 2026-07-17 · auto
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient …
CVE-2026-50314 · 2026-07-16 · auto
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-50301 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55140 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55133 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
CVE-2026-55033 · 2026-07-16 · auto
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55032 · 2026-07-16 · auto
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55022 · 2026-07-16 · auto
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55018 · 2026-07-16 · auto
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55017 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-50467 · 2026-07-16 · auto
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-47290 · 2026-07-16 · auto
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-56193 · 2026-07-16 · auto
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-55126 · 2026-07-16 · auto
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-55125 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55123 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55056 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55055 · 2026-07-16 · auto
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55052 · 2026-07-16 · auto
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-55049 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55045 · 2026-07-16 · auto
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-55043 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
CVE-2026-55039 · 2026-07-16 · auto
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55038 · 2026-07-16 · auto
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55036 · 2026-07-16 · auto
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55044 · 2026-07-16 · auto
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55041 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55037 · 2026-07-16 · auto
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.