|
421
|
6.4 |
MEDIUM
Local
|
-
|
-
|
Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker w…
New
|
CWE-77
Command Injection
|
CVE-2026-35070
|
2026-05-20 22:56 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
422
|
7.5 |
HIGH
Network
|
-
|
-
|
The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. T…
New
|
CWE-89
SQL Injection
|
CVE-2026-3985
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
423
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This is due to missing autho…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5293
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
424
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and including 2.4.2.6. The plugin prote…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-6072
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
425
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect no…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6391
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
426
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce validation on the bigf…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6452
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
427
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6549
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
428
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-6394
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
429
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. This is due to the complete absence of n…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-6395
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
430
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up to and including 2.5.6. This is due to insufficien…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6397
|
2026-05-20 22:54 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|