A vulnerability described as problematic has been identified in BEAR Plugin up to 1.2.1 on WordPress. This issue affects some unknown processing. The manipulation results in cross-site request forgery.
This vulnerability is cataloged as CVE-2026-84023. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as problematic has been found in BEAR Plugin up to 1.2.1 on WordPress. Impacted is an unknown function of the component Configuration. This manipulation causes cross-site request forgery.
This vulnerability is registered as CVE-2026-84024. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Masteriyo LMS Plugin up to 3.4.0 on WordPress. Affected by this vulnerability is an unknown functionality. Such manipulation leads to authorization bypass.
This vulnerability is referenced as CVE-2026-82851. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability marked as problematic has been reported in Masteriyo LMS Plugin up to 3.4.0 on WordPress. This vulnerability affects unknown code. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-82847. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Masteriyo LMS Plugin up to 3.4.0 on WordPress. Affected is an unknown function. Such manipulation leads to deserialization.
This vulnerability is listed as CVE-2026-82845. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in BE REST Endpoints Plugin up to 1.0.0 on WordPress. It has been rated as problematic. Affected is an unknown function. This manipulation causes cross site scripting.
The identification of this vulnerability is CVE-2026-81742. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in WPBakery Export & Import WPBakery Page Builder Plugin up to 1.0.2 on WordPress. The affected element is an unknown function of the component Template Import. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-81429. The attack can be executed remotely. There is not any exploit available.
A vulnerability identified as critical has been detected in DS Ad Rotator Plugin up to 0.8 on WordPress. This impacts an unknown function of the component Image Upload Handler. This manipulation causes unrestricted upload.
This vulnerability is tracked as CVE-2026-81402. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability marked as problematic has been reported in Gpx2Graphics Plugin up to 0.3 on WordPress. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in unrestricted upload.
This vulnerability is cataloged as CVE-2026-81090. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Yogeta WP Cloud Plugin up to 1.0 on WordPress. It has been declared as problematic. This impacts an unknown function. The manipulation results in files or directories accessible.
This vulnerability was named CVE-2026-80494. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in SureRank SEO Plugin up to 1.10.0 on WordPress and classified as problematic. The impacted element is an unknown function. Executing a manipulation can lead to information disclosure.
This vulnerability is handled as CVE-2026-78152. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability was found in SAMO Forms Plugin up to 1.0.0 on WordPress. It has been classified as critical. This affects an unknown function. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-80491. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability labeled as critical has been found in Apache Tomcat up to 11.0.24/10.1.57/9.0.120/8.5.100. This affects an unknown function of the component Rewrite Valve. The manipulation results in off-by-one.
This vulnerability is known as CVE-2026-65927. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability was found in Apache Tomcat up to 11.0.24/10.1.57/9.0.120. It has been classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper input validation.
This vulnerability is documented as CVE-2026-65637. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability described as problematic has been identified in Apache Tomcat up to 9.0.120/10.1.57/11.0.24. The impacted element is an unknown function of the component Unix Domain Socket. The manipulation results in time-of-check time-of-use.
This vulnerability was named CVE-2026-65183. The attack needs to be approached locally. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.120/10.1.57/11.0.24 and classified as critical. Affected is an unknown function. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2026-65182. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Jwcrypto. This affects an unknown function. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-80179. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in gRPC-Go up to 1.83.0 and classified as problematic. The affected element is an unknown function of the file internal/transport/transport.go of the component Transport. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-84304. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.