CVE Find is a real-time vulnerability database indexing 378 345 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 3982 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-18316 |
2026-08-16 06h16 +00:00 |
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data du... Authorization problems |
9.1 |
Critical |
|
CVE-2026-17123 |
2026-08-16 05h16 +00:00 |
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in vers... Server-Side Request Forgery - SSRF |
8.8 |
High |
|
CVE-2026-16099 |
2026-08-16 05h16 +00:00 |
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to i... |
8.8 |
High |
|
CVE-2026-16098 |
2026-08-16 05h16 +00:00 |
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all version... File Inclusion |
9.8 |
Critical |
|
CVE-2026-14524 |
2026-08-16 05h16 +00:00 |
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insuf... Directory Traversal |
9.1 |
Critical |
|
CVE-2026-14498 |
2026-08-16 05h16 +00:00 |
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to... File Inclusion |
8.8 |
High |
|
CVE-2026-18432 |
2026-08-16 04h24 +00:00 |
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all v... Improper Privilege Management |
9.8 |
Critical |
|
CVE-2026-19924 |
2026-08-16 01h00 +00:00 |
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability... Authorization problems |
9.3 |
Critical |
|
CVE-2026-73053 |
2026-08-15 22h16 +00:00 |
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func... Cross-site Scripting |
9 |
Critical |
|
CVE-2026-73052 |
2026-08-15 22h16 +00:00 |
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d... Cross-site Scripting |
9 |
Critical |