|
41
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The FundPress – WordPress Donation Plugin for WordPress is vulnerable to authorization bypass in versions up to and including 2.0.8. This is due to missing authorization and nonce verification in the…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4650
|
2026-05-2 17:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
8.8 |
HIGH
Network
|
-
|
-
|
The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.2 via…
New
|
CWE-94
Code Injection
|
CVE-2026-2052
|
2026-05-2 17:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMu…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7605
|
2026-05-2 16:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: vidtv: fix pass-by-value structs causing MSAN warnings
vidtv_ts_null_write_into() and vidtv_ts_pcr_write_into() take their…
New
|
-
|
CVE-2026-43058
|
2026-05-2 16:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ctxfi: Fix missing SPDIFI1 index handling
SPDIF1 DAIO type isn't properly handled in daio_device_index() for
hw20k2, and it…
New
|
-
|
CVE-2026-31776
|
2026-05-2 16:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
8.1 |
HIGH
Network
|
-
|
-
|
The Profile Builder Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 3.14.5. This is due to the use of PHP's maybe_unserialize() function on the atta…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-7647
|
2026-05-2 15:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
7.2 |
HIGH
Network
|
-
|
-
|
The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 12.5.0.1 via the scan_video. This makes …
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7049
|
2026-05-2 15:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sg_content_number_prefix' param…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6916
|
2026-05-2 15:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Ona theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.26 via the ona_activate_child_theme. This makes it possible for authenticated attacker…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6812
|
2026-05-2 15:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Call for Price for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.2.0 due to insufficient input sanitizat…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6447
|
2026-05-2 15:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|