| unknown |
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-16 |
| unknown |
CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability |
advisory |
vendor-blogs |
|
|
2026-08-16 |
| critical |
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability |
advisory |
vendor-blogs |
|
rce |
2026-08-16 |
| unknown |
CVE-2026-74251 — Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0… |
vulnerability |
nvd |
CVE-2026-74251 |
|
2026-08-16 |
| high |
CVE-2026-74578 — In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force s… |
vulnerability |
nvd |
CVE-2026-74578 |
|
2026-08-16 |
| high |
CVE-2026-2497 — The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_ord… |
vulnerability |
nvd |
CVE-2026-2497 |
|
2026-08-16 |
| medium |
CVE-2026-2357 — The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… |
vulnerability |
nvd |
CVE-2026-2357 |
|
2026-08-16 |
| medium |
CVE-2026-17608 — The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cro… |
vulnerability |
nvd |
CVE-2026-17608 |
|
2026-08-16 |
| medium |
CVE-2026-17604 — The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable t… |
vulnerability |
nvd |
CVE-2026-17604, CVE-2026-18347 |
|
2026-08-16 |
| high |
CVE-2026-17087 — The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerab… |
vulnerability |
nvd |
CVE-2026-17087 |
|
2026-08-16 |
| high |
CVE-2026-13424 — The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to… |
vulnerability |
nvd |
CVE-2026-13424 |
|
2026-08-16 |
| medium |
CVE-2026-12998 — The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln… |
vulnerability |
nvd |
CVE-2026-12998 |
|
2026-08-16 |
| high |
CVE-2026-10734 — The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_recor… |
vulnerability |
nvd |
CVE-2026-10734 |
|
2026-08-16 |
| medium |
CVE-2026-9767 — The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic S… |
vulnerability |
nvd |
CVE-2026-9767 |
|
2026-08-16 |
| medium |
CVE-2026-2283 — The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' paramet… |
vulnerability |
nvd |
CVE-2026-2283 |
|
2026-08-16 |
| medium |
CVE-2026-19934 — A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unkno… |
vulnerability |
nvd |
CVE-2026-19934 |
|
2026-08-16 |
| high |
CVE-2026-19728 — The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify th… |
vulnerability |
nvd |
CVE-2026-19728 |
|
2026-08-16 |
| medium |
CVE-2026-19726 — The Visualizer WordPress plugin before 4.0.7 does not properly authorise access to the configuration… |
vulnerability |
nvd |
CVE-2026-19726 |
|
2026-08-16 |
| critical |
CVE-2026-19725 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value… |
vulnerability |
nvd |
CVE-2026-19725 |
|
2026-08-16 |
| high |
CVE-2026-19717 — The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisat… |
vulnerability |
nvd |
CVE-2026-19717 |
|
2026-08-16 |
| critical |
CVE-2026-19714 — The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google iden… |
vulnerability |
nvd |
CVE-2026-19714 |
|
2026-08-16 |
| medium |
CVE-2026-19712 — The Masteriyo LMS WordPress plugin before 2.3.3 does not sanitise and escape a quiz field before out… |
vulnerability |
nvd |
CVE-2026-19712 |
|
2026-08-16 |
| medium |
CVE-2026-19711 — The Premium Packages WordPress plugin before 7.0.7 does not validate a withdrawal request against th… |
vulnerability |
nvd |
CVE-2026-19711 |
|
2026-08-16 |
| medium |
CVE-2026-19613 — The ECS WordPress plugin before 4.3.10 does not perform ownership or post-status checks when one of… |
vulnerability |
nvd |
CVE-2026-19613 |
|
2026-08-16 |
| high |
CVE-2026-18653 — The WP Directory Kit WordPress plugin before 1.5.7 does not sanitise and escape a parameter before u… |
vulnerability |
nvd |
CVE-2026-18653 |
|
2026-08-16 |
| medium |
CVE-2026-18402 — The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cr… |
vulnerability |
nvd |
CVE-2026-18402 |
ransomware |
2026-08-16 |
| critical |
CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data du… |
vulnerability |
nvd |
CVE-2026-18316 |
|
2026-08-16 |
| medium |
CVE-2026-17582 — The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to,… |
vulnerability |
nvd |
CVE-2026-17582 |
|
2026-08-16 |
| high |
CVE-2026-17581 — The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code In… |
vulnerability |
nvd |
CVE-2026-17581 |
rce |
2026-08-16 |
| high |
CVE-2026-17533 — The All-in-One WP Migration and Backup WordPress plugin before 7.108 does not restrict its migration… |
vulnerability |
nvd |
CVE-2026-17533 |
|
2026-08-16 |
| medium |
CVE-2026-16775 — The Smash Balloon Social Post Feed – Simple Social Feeds for WordPress plugin for WordPress is vulne… |
vulnerability |
nvd |
CVE-2026-16775 |
|
2026-08-16 |
| medium |
CVE-2026-16758 — The Snippet Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortco… |
vulnerability |
nvd |
CVE-2026-16758 |
|
2026-08-16 |
| medium |
CVE-2026-15790 — The Youtube Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… |
vulnerability |
nvd |
CVE-2026-15790 |
|
2026-08-16 |
| medium |
CVE-2026-15604 — The Toocheke Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… |
vulnerability |
nvd |
CVE-2026-15604 |
|
2026-08-16 |
| medium |
CVE-2026-15384 — The Manual Image Crop WordPress plugin before 1.15 does not perform any capability check or nonce ve… |
vulnerability |
nvd |
CVE-2026-15384 |
|
2026-08-16 |
| medium |
CVE-2026-15351 — The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPr… |
vulnerability |
nvd |
CVE-2026-15351 |
|
2026-08-16 |
| medium |
CVE-2026-15345 — The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnera… |
vulnerability |
nvd |
CVE-2026-15345 |
|
2026-08-16 |
| medium |
CVE-2026-15056 — The StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin… |
vulnerability |
nvd |
CVE-2026-15056 |
|
2026-08-16 |
| medium |
CVE-2026-13712 — The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow modul… |
vulnerability |
nvd |
CVE-2026-13712 |
|
2026-08-16 |
| medium |
CVE-2026-10035 — The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to PHP Object Injection in all… |
vulnerability |
nvd |
CVE-2026-10035 |
|
2026-08-16 |
| medium |
CVE-2026-19933 — A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0.… |
vulnerability |
nvd |
CVE-2026-19933 |
|
2026-08-16 |
| medium |
CVE-2026-19932 — A security flaw has been discovered in DefaultFuction Notice-System-Managent 2.0. This issue affects… |
vulnerability |
nvd |
CVE-2026-19932 |
|
2026-08-16 |
| critical |
CVE-2026-18432 — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all v… |
vulnerability |
nvd |
CVE-2026-18432 |
|
2026-08-16 |
| medium |
CVE-2026-18385 — The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restri… |
vulnerability |
nvd |
CVE-2026-18385 |
ransomware |
2026-08-16 |
| high |
CVE-2026-17123 — The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in vers… |
vulnerability |
nvd |
CVE-2026-17123 |
ransomware |
2026-08-16 |
| medium |
CVE-2026-16779 — The Kubio AI Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions… |
vulnerability |
nvd |
CVE-2026-16779 |
|
2026-08-16 |
| high |
CVE-2026-16099 — The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to i… |
vulnerability |
nvd |
CVE-2026-16099 |
rce |
2026-08-16 |
| critical |
CVE-2026-16098 — The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all version… |
vulnerability |
nvd |
CVE-2026-16098 |
rce |
2026-08-16 |
| medium |
CVE-2026-16079 — The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attri… |
vulnerability |
nvd |
CVE-2026-16079 |
|
2026-08-16 |
| medium |
CVE-2026-15726 — The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Sho… |
vulnerability |
nvd |
CVE-2026-15726 |
|
2026-08-16 |