CVE Find is a real-time vulnerability database indexing 398 384 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2849 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-82901 |
2026-09-26 18h28 +00:00 |
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due ... File Inclusion |
9.8 |
Critical |
|
CVE-2026-77203 |
2026-09-26 18h16 +00:00 |
The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escala... Improper Privilege Management |
8.8 |
High |
|
CVE-2026-85984 |
2026-09-26 17h28 +00:00 |
The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to A... Authorization problems |
9.8 |
Critical |
|
CVE-2026-97163 |
2026-09-26 14h33 +00:00 |
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0... Directory Traversal |
10 |
Critical |
|
CVE-2026-100717 |
2026-09-26 14h16 +00:00 |
froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl reje... |
9.9 |
Critical |
|
CVE-2026-100716 |
2026-09-26 14h16 +00:00 |
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (... |
9.9 |
Critical |
|
CVE-2026-100715 |
2026-09-26 14h16 +00:00 |
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP dat... |
9.6 |
Critical |
|
CVE-2026-100714 |
2026-09-26 14h16 +00:00 |
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlik... |
9.1 |
Critical |
|
CVE-2026-100706 |
2026-09-26 14h16 +00:00 |
kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath... |
9.9 |
Critical |
|
CVE-2026-100697 |
2026-09-26 14h16 +00:00 |
Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.... Server-Side Request Forgery - SSRF |
8.6 |
High |