Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 328/436
5.3
CVE-2026-14313

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-

5.3
CVE-2026-14314

The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel

5.3
CVE-2026-14547

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t

5.3
CVE-2026-16290

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member

5.3
CVE-2026-19011

A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa

5.3
CVE-2026-11983

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up

5.3
CVE-2026-0673

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to

5.3
CVE-2026-19039

A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted

5.3
CVE-2026-19044

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of

5.3
CVE-2026-19045

A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog

5.3
CVE-2026-28169

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

5.3
CVE-2026-28180

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

5.3
CVE-2026-32469

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

5.3
CVE-2026-32548

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

5.3
CVE-2026-65502

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

5.3
CVE-2026-66683

Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.

5.3
CVE-2026-66684

Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.

5.3
CVE-2026-66685

Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.

5.3
CVE-2026-66699

Custom role Broken Access Control in Dokan <= 5.0.10 versions.

5.3
CVE-2026-66701

Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

5.3
CVE-2026-19047

A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/e

5.3
CVE-2026-12501

The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent

5.3
CVE-2026-13342

The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base

5.3
CVE-2026-14831

The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat

5.3
CVE-2026-14842

The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b

5.3
CVE-2026-14936

The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s

5.3
CVE-2026-15147

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen

5.3
CVE-2026-15149

The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar

5.3
CVE-2026-15152

The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment

5.3
CVE-2026-15208

The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p

5.3
CVE-2026-16067

The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the

5.3
CVE-2026-19054

A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec

5.3
CVE-2026-19058

A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter

5.3
CVE-2026-19060

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulat

5.3
CVE-2026-19108

A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetVa

5.3
CVE-2026-19146

Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromis

5.3
CVE-2026-48077

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.3
CVE-2026-48078

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.3
CVE-2026-61632

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2

5.3
CVE-2026-71433

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin

5.3
CVE-2026-71434

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms

5.3
CVE-2026-71554

h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header

5.3
CVE-2026-12261

A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 allows for cross-package resource and model poisonin

5.3
CVE-2026-15148

The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates fro

5.3
CVE-2026-15239

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache

5.3
CVE-2026-49006

By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss

5.3
CVE-2026-19206

A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT

5.3
CVE-2026-66062

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the c

5.3
CVE-2026-19229

A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functiona

5.3
CVE-2025-71410

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started