CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-91010

4.3

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests …

WordPress
Details

CVE-2026-91009

4.3

The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, …

WordPress
Details

CVE-2026-91008

3.7

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' …

WordPress
Details

CVE-2026-87935

8.1

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization …

Apache
Details

CVE-2026-87796

9.8

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due …

WordPress
Details

CVE-2026-50604

4.9

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the …

Acer
Details

CVE-2026-25290

7.8

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

Details

CVE-2026-25284

7.3

Information Disclosure when a pointer is reused after being deallocated.

Information
Details

CVE-2026-25283

8.8

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Details
140/9161