🛡️ CVE Intelligence Center
Common Vulnerabilities & Exposures — Security Intelligence Database
| CVE ID | Severity | CVSS | Description | Status | Published |
|---|---|---|---|---|---|
| CVE-2026-3335 | Medium | 5.3 |
The Canto plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.1.1 via th…
|
— | Mar 21, 2026 |
| CVE-2026-3641 | Medium | 5.3 |
The Appmax plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.0.3. …
|
— | Mar 21, 2026 |
| CVE-2026-1253 | Medium | 5.3 |
The Group Chat & Video Chat by AtomChat plugin for WordPress is vulnerable to unauthorized modification of data due to a…
|
— | Mar 21, 2026 |
| CVE-2026-3567 | Medium | 5.3 |
The RepairBuddy – Repair Shop CRM & Booking Plugin for WordPress is vulnerable to unauthorized access in all versions up…
|
— | Mar 21, 2026 |
| CVE-2026-32046 | Medium | 5.3 |
OpenClaw versions prior to 2026.2.21 contain an improper sandbox configuration vulnerability that allows attackers to ex…
|
— | Mar 21, 2026 |
| CVE-2026-3506 | Medium | 5.3 |
The WP-Chatbot for Messenger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu…
|
— | Mar 21, 2026 |
| CVE-2026-2756 | Medium | 5.0 |
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the…
|
— | Mar 21, 2026 |
| CVE-2025-43520 | Critical | 9.8 |
Apple Multiple Products — CVE-2025-43520
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain a classic buffer …
|
— | Mar 20, 2026 |
| CVE-2025-43510 | Critical | 9.8 |
Apple Multiple Products — CVE-2025-43510
Apple watchOS, iOS, iPadOS, macOS, visionOS, and tvOS contain an improper locki…
|
— | Mar 20, 2026 |
| CVE-2025-32432 | Critical | 9.8 |
Craft CMS Craft CMS — CVE-2025-32432
Craft CMS contains a code injection vulnerability that allows a remote attacker to …
|
— | Mar 20, 2026 |
| CVE-2025-31277 | Critical | 9.8 |
Apple Multiple Products — CVE-2025-31277
Apple Safari, iOS, watchOS, visionOS, iPadOS, macOS, and tvOS contain a buffer …
|
— | Mar 20, 2026 |
| CVE-2025-54068 | Critical | 9.8 |
Laravel Livewire — CVE-2025-54068
Laravel Livewire contain a code injection vulnerability that could allow unauthenticat…
|
— | Mar 20, 2026 |
| CVE-2026-33136 | Critical | 9.3 |
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)…
|
⚡ Exploit ✅ Patch | Mar 20, 2026 |
| CVE-2026-33135 | Critical | 9.3 |
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS)…
|
⚡ Exploit ✅ Patch | Mar 20, 2026 |
| CVE-2026-2421 | Medium | 6.5 |
The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an…
|
— | Mar 20, 2026 |
| CVE-2026-4485 | Medium | 6.3 |
A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown functio…
|
— | Mar 20, 2026 |
| CVE-2026-4500 | Medium | 6.3 |
A vulnerability was identified in bagofwords1 bagofwords up to 0.0.297. This impacts the function generate_df of the fil…
|
— | Mar 20, 2026 |
| CVE-2026-4506 | Medium | 6.3 |
A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core…
|
— | Mar 20, 2026 |
| CVE-2026-4505 | Medium | 6.3 |
A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh…
|
— | Mar 20, 2026 |
| CVE-2026-4472 | Medium | 6.3 |
A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability a…
|
— | Mar 20, 2026 |