|
291
|
- |
|
-
|
-
|
sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not include a capability mode check restricting signal de…
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-45259
|
2026-06-27 18:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292
|
- |
|
-
|
-
|
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition could overflow, so that a large offset and length …
New
|
CWE-125 CWE-190 CWE-681 CWE-787
Out-of-bounds Read Integer Overflow or Wraparound Incorrect Conversion between Numeric Types Out-of-bounds Write
|
CVE-2026-45258
|
2026-06-27 18:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authent…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-9242
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not pr…
New
|
CWE-862
Missing Authorization
|
CVE-2026-9233
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'process_batch' functions in all versions up to, and i…
New
|
CWE-862
Missing Authorization
|
CVE-2026-3462
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-13295
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Spexo theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the activate_plugin function in all versions up to, and including, 2.0.11. This makes it possib…
New
|
CWE-862
Missing Authorization
|
CVE-2026-12471
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. The handler is regis…
New
|
CWE-862
Missing Authorization
|
CVE-2026-12432
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.8.0 due to i…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-12399
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-11987
|
2026-06-27 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|