Vulnerabilities

Recent vulnerabilities

Recent vulnerabilities from
Select from 81 available sources using the dropdown above.

GitHub 🐙

Recent vulnerabilities · 379691 entries
ID Severity Description Published Updated
ghsa-vc58-2rcj-cgf8
7.5 (3.1)
The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all ver… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-9949-jq7q-8g48
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly valida… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-82gv-pr29-8vm2
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCA… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-7cq6-x444-93vj
7.2 (3.1)
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable t… 2026-10-02T06:30:55Z 2026-10-02T06:30:56Z
ghsa-564m-jf3j-p556
The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted b… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-3v9p-5xxf-6hxg
8.1 (3.1)
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in a… 2026-10-02T06:30:56Z 2026-10-02T06:30:56Z
ghsa-whfp-wchg-v9xw
The Motors WordPress plugin before 1.4.124 does not properly verify that a user is authorised to m… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-r39q-9952-j46j
9.1 (3.1)
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversa… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-h8h9-7p7r-7rpq
8.8 (3.1)
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalati… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-h25v-5897-j3vf
The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting be… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-fcq7-9xcx-6xxw
5.4 (3.1)
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Autho… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-f5pm-cq7v-xmjw
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its a… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-87mc-m7h4-wxp9
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-7hr3-mm9w-ghgw
6.1 (3.1)
The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflec… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-3fm8-276x-m74x
The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value b… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-2xw5-r48v-m7fg
The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genu… 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-24j4-6qf8-p4rw
The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one … 2026-10-02T06:30:55Z 2026-10-02T06:30:55Z
ghsa-xwfv-9j83-wfj7
9.8 (3.1)
The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-x36m-2pwv-jrpp
7.2 (3.1)
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-m8mq-x2gc-8xcm
7.2 (3.1)
The CTX Feed Pro plugin for WordPress is vulnerable to Code Injection in all versions up to, and in… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-gcf4-jm96-42wg
The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce prod… 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-fwjj-2936-g23h
9.8 (3.1)
The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up … 2026-10-02T06:30:54Z 2026-10-02T06:30:54Z
ghsa-xv62-77m9-3736
9.8 (3.1)
9.3 (4.0)
A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the functio… 2026-06-08T09:32:00Z 2026-10-02T06:30:52Z
ghsa-r329-fjhj-3cw3
7.8 (3.1)
A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtp… 2026-08-10T21:32:08Z 2026-10-02T06:30:52Z
ghsa-f3xc-chgr-4vvj
7.8 (3.1)
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible 2022-07-29T00:00:48Z 2026-10-02T06:30:52Z
ghsa-6jq9-9f7w-h7mc
7.8 (3.1)
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerabi… 2026-08-20T12:31:21Z 2026-10-02T06:30:52Z
ghsa-v78q-44mm-wf7q
7.3 (3.1)
5.5 (4.0)
A security vulnerability has been detected in modelcontextprotocol mcp-server-fetch and mcp-server-… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-r4mc-xrrj-f33f
6.3 (3.1)
2.1 (4.0)
A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-qc9g-wj38-hfvp
7.5 (3.1)
Transmission of a sensitive key in the URL over an unencrypted HTTP connection.  The request is sen… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z
ghsa-mwfx-8rgq-rc8f
7.5 (3.1)
An API key is hardcoded and retrievable from the application package. Since Android applications ca… 2026-10-02T03:31:10Z 2026-10-02T03:31:10Z