CVE Find est une base de données de vulnérabilités en temps réel, indexant 401 018 failles de sécurité (CVE) issues de MITRE, NVD, CISA KEV, CWE et CAPEC. 2623 nouvelles CVE ont été publiées ces 7 derniers jours.
Données agrégées depuis : MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Publié | Description | Score | Gravité | |
|---|---|---|---|---|---|
CVE-2026-96451 |
2026-10-03 16h16 +00:00 |
Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ul... Authorization problems |
8.8 |
Haute |
|
CVE-2026-103065 |
2026-10-03 15h16 +00:00 |
Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Acces... Input Validation |
8.2 |
Haute |
|
CVE-2026-105115 |
2026-10-03 14h16 +00:00 |
OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the ... Authorization problems |
8.6 |
Haute |
|
CVE-2026-105105 |
2026-10-03 11h55 +00:00 |
CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command b... Authorization problems |
9.8 |
Critique |
|
CVE-2026-92084 |
2026-10-03 08h16 +00:00 |
The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulner... Code Injection |
9.1 |
Critique |
|
CVE-2026-87115 |
2026-10-03 07h16 +00:00 |
The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file d... Directory Traversal |
9.1 |
Critique |
|
CVE-2026-18443 |
2026-10-03 07h16 +00:00 |
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is ... SQL Injection |
8.8 |
Haute |
|
CVE-2026-91078 |
2026-10-03 06h16 +00:00 |
The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the... Authorization problems |
8.2 |
Haute |
|
CVE-2026-89236 |
2026-10-03 06h16 +00:00 |
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters befo... SQL Injection |
8.6 |
Haute |
|
CVE-2026-88783 |
2026-10-03 06h16 +00:00 |
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed H... Cross-site Scripting |
8.8 |
Haute |