CVE Find is a real-time vulnerability database indexing 401 018 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2633 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-96451 |
2026-10-03 16h16 +00:00 |
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ul... Authorization problems |
8.8 |
High |
|
CVE-2026-103065 |
2026-10-03 15h16 +00:00 |
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Acces... Input Validation |
8.2 |
High |
|
CVE-2026-105115 |
2026-10-03 14h16 +00:00 |
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the ... Authorization problems |
8.6 |
High |
|
CVE-2026-105105 |
2026-10-03 11h55 +00:00 |
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command b... Authorization problems |
9.8 |
Critical |
|
CVE-2026-92084 |
2026-10-03 08h16 +00:00 |
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulner... Code Injection |
9.1 |
Critical |
|
CVE-2026-87115 |
2026-10-03 07h16 +00:00 |
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file d... Directory Traversal |
9.1 |
Critical |
|
CVE-2026-18443 |
2026-10-03 07h16 +00:00 |
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is ... SQL Injection |
8.8 |
High |
|
CVE-2026-91078 |
2026-10-03 06h16 +00:00 |
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the... Authorization problems |
8.2 |
High |
|
CVE-2026-89236 |
2026-10-03 06h16 +00:00 |
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters befo... SQL Injection |
8.6 |
High |
|
CVE-2026-88783 |
2026-10-03 06h16 +00:00 |
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed H... Cross-site Scripting |
8.8 |
High |