Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,570
Critical1,293
High4,448
Medium12,545
Reset
Showing 5281-5300 of 18570 records
Threat Entry Updated 2026-01-16

CVE-2026-22694 - Aliasvault Plugin

AliasVault is a privacy-first password manager with built-in email aliasing. AliasVault Android versions 0.24.0 through 0.25.2 contained an issue in how passkey requests from Android apps were validated. Under certain local conditions, a malicious app could attempt to obtain a passkey response for a site it was not authorized to access. The issue involved incomplete validation of calling app identity, origin, and RP ID in the Android credential provider. This issue was fixed in AliasVault Android 0.25.3.

PLUGIN Aliasvault

CVE-2026-22694

MEDIUM CVSS 6.1 2026-01-14
Threat Entry Updated 2026-01-23

CVE-2026-21889 - Weblate Plugin

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

PLUGIN Weblate

CVE-2026-21889

LOW CVSS 2.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2026-22211 - TinyOS Plugin

TinyOS versions up to and including 2.1.2 contain a global buffer overflow vulnerability in the printfUART formatted output implementation used within the ZigBee / IEEE 802.15.4 networking stack. The implementation formats output into a fixed-size global buffer and concatenates strings for %s format specifiers using strcat() without verifying remaining buffer capacity. When printfUART is invoked with a caller-controlled string longer than the available space, the unbounded sprintf/strcat sequence writes past the end of debugbuf, resulting in global memory corruption. This can cause denial of service, unintended behavior, or information disclosure…

PLUGIN TinyOS

CVE-2026-22211

MEDIUM CVSS 5.1 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22240 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unauthenticated APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable users API to retrieve the plaintext passwords of all user users. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform by logging in using an exposed admin email address and password.

PLUGIN BLUVOYIX

CVE-2026-22240

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22239 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to design flaws in the email sending API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable email sending API. Successful exploitation of this vulnerability could allow the attacker to send unsolicited emails to anyone on behalf of the company.

PLUGIN BLUVOYIX

CVE-2026-22239

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22238 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX admin APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable admin API to create a new user with admin privileges. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform by logging in to the newly-created admin user.

PLUGIN BLUVOYIX

CVE-2026-22238

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-01-20

CVE-2026-22820 - Outray Plugin

Outray openSource ngrok alternative. Prior to 0.1.5, a TOCTOU race condition vulnerability allows a user to exceed the set number of active tunnels in their subscription plan. This vulnerability is fixed in 0.1.5.

PLUGIN Outray

CVE-2026-22820

MEDIUM CVSS 6.3 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22237 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to the exposure of sensitive internal API documentation. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the APIs exposed by the documentation. Successful exploitation of this vulnerability could allow the attacker to cause damage to the targeted platform by abusing internal functionality.

PLUGIN BLUVOYIX

CVE-2026-22237

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-02-02

CVE-2026-22236 - BLUVOYIX Plugin

The vulnerability exists in BLUVOYIX due to improper authentication in the BLUVOYIX backend APIs. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable APIs. Successful exploitation of this vulnerability could allow the attacker to gain full access to customers' data and completely compromise the targeted platform.

PLUGIN BLUVOYIX

CVE-2026-22236

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2026-0532 - Kibana Plugin

External Control of File Name or Path (CWE-73) combined with Server-Side Request Forgery (CWE-918) can allow an attacker to cause arbitrary file disclosure through a specially crafted credentials JSON payload in the Google Gemini connector configuration. This requires an attacker to have authenticated access with privileges sufficient to create or modify connectors (Alerts & Connectors: All). The server processes a configuration without proper validation, allowing for arbitrary network requests and for arbitrary file reads.

PLUGIN Kibana

CVE-2026-0532

HIGH CVSS 8.6 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2026-0529 - Packetbeat Plugin

Improper Validation of Array Index (CWE-129) in Packetbeat’s MongoDB protocol parser can allow an attacker to cause Overflow Buffers (CAPEC-100) through specially crafted network traffic. This requires an attacker to send a malformed payload to a monitored network interface where MongoDB protocol parsing is enabled.

PLUGIN Packetbeat

CVE-2026-0529

MEDIUM CVSS 6.5 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-23550 - Modular DS Plugin

Incorrect Privilege Assignment vulnerability in Modular DS Modular DS modular-connector allows Privilege Escalation.This issue affects Modular DS: from n/a through

PLUGIN Modular DS

CVE-2026-23550

CRITICAL CVSS 10.0 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0813 - Short Link Plugin

The Short Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'short_link_post_title' and 'short_link_page_title' parameters in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.

PLUGIN Short Link

CVE-2026-0813

MEDIUM CVSS 4.4 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0812 - Linkedin Sc Plugin

The LinkedIn SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'linkedin_sc_date_format', 'linkedin_sc_api_key', and 'linkedin_sc_secret_key' parameters in all versions up to, and including, 1.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the injected page.

PLUGIN Linkedin Sc

CVE-2026-0812

MEDIUM CVSS 4.4 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0741 - Electric Studio Download Counter Plugin

The Electric Studio Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Electric Studio Download Counter

CVE-2026-0741

MEDIUM CVSS 4.4 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0739 - Wmf Mobile Redirector Plugin

The WMF Mobile Redirector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Wmf Mobile Redirector

CVE-2026-0739

MEDIUM CVSS 4.4 2026-01-14
Threat Entry Updated 2026-06-17

CVE-2026-0734 - Wp Allow Hosts Plugin

The WP Allowed Hosts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allowed-hosts' parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

PLUGIN Wp Allow Hosts

CVE-2026-0734

MEDIUM CVSS 4.4 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15513 - Float Gateway Plugin

The Float Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to improper error handling in the verifyFloatResponse() function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to mark any WooCommerce order as failed.

PLUGIN Float Gateway

CVE-2025-15513

MEDIUM CVSS 5.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15512 - Aplazo Payment Gateway Plugin

The Aplazo Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the check_success_response() function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to set any WooCommerce order to `pending payment` status.

PLUGIN Aplazo Payment Gateway

CVE-2025-15512

MEDIUM CVSS 5.3 2026-01-14
Threat Entry Updated 2026-01-14

CVE-2025-15475 - Payhere Payment Gateway Plugin

The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of pending WooCommerce orders to paid/completed/on hold.

PLUGIN Payhere Payment Gateway

CVE-2025-15475

MEDIUM CVSS 5.3 2026-01-14
Scroll to top