|
3971
|
8.8 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
|
CWE-77
Command Injection
|
CVE-2026-44871
|
2026-05-14 23:29 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3972
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.…
|
CWE-89
SQL Injection
|
CVE-2026-5486
|
2026-05-14 23:29 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3973
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in th…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5361
|
2026-05-14 23:29 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3974
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.9. This is due to the plugin not properly verifying tha…
|
CWE-862
Missing Authorization
|
CVE-2026-7525
|
2026-05-14 23:29 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3975
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-7648
|
2026-05-14 23:29 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3976
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.2…
|
CWE-80
Basic XSS
|
CVE-2025-15345
|
2026-05-14 23:29 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3977
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks…
|
CWE-862
Missing Authorization
|
CVE-2026-3829
|
2026-05-14 23:29 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3978
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to stored cross-site scripting via the `menu_hover_click` …
|
CWE-79
Cross-site Scripting
|
CVE-2026-5243
|
2026-05-14 23:28 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3979
|
8.2 |
HIGH
Network
|
-
|
-
|
The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 6.1.21. This is due to the SubmissionPolicy class authori…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-5396
|
2026-05-14 23:28 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3980
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The GLS Shipping for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'failed_orders' parameter in all versions up to, and including, 1.4.0 due to insufficient…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6417
|
2026-05-14 23:28 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|