Количество 386 296
Количество 386 296
CVE-2026-57351
Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions.
CVE-2026-57350
Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions.
CVE-2026-5734
Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.
CVE-2026-57349
Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions.
CVE-2026-57348
Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions.
CVE-2026-57347
Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.
CVE-2026-57346
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3.
CVE-2026-57345
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
CVE-2026-57344
Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions.
CVE-2026-57343
Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions.
CVE-2026-57342
Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.
CVE-2026-57341
Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions.
CVE-2026-57340
Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions.
CVE-2026-5733
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2.
CVE-2026-57339
Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions.
CVE-2026-57338
Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.
CVE-2026-57337
Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions.
CVE-2026-57336
Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions.
CVE-2026-57335
Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions.
CVE-2026-57334
Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-57351 Unauthenticated Cross Site Scripting (XSS) in HandL UTM Grabber <= 2.9.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57350 Unauthenticated Cross Site Scripting (XSS) in WP Debugging <= 2.12.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-5734 Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1. | CVSS3: 9.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-57349 Unauthenticated Cross Site Scripting (XSS) in WPeMatico RSS Feed Fetcher <= 2.8.17 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57348 Unauthenticated Server Side Request Forgery (SSRF) in Paid Member Subscriptions <= 3.0.4 versions. | CVSS3: 7.2 | 0% Низкий | 2 месяца назад | |
CVE-2026-57347 Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57346 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from n/a through 1.12.3. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57345 Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57344 Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.4.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57343 Unauthenticated Cross Site Scripting (XSS) in Real Estate 7 <= 3.5.9 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57342 Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57341 Unauthenticated Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57340 Unauthenticated Broken Access Control in Japanized For WooCommerce <= 2.9.12 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-5733 Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thunderbird 149.0.2. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
CVE-2026-57339 Unauthenticated Broken Access Control in Business Directory <= 6.4.23 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57338 Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57337 Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57336 Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions. | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-57335 Subscriber Broken Access Control in Ads by WPQuads <= 3.0.3 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-57334 Unauthenticated Broken Access Control in WP User Frontend <= 4.3.7 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад |
Уязвимостей на страницу