Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-66605 Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. No fix yet Fix from $4,9002026-08-20 HIGH 7.1 CVE-2026-66604 Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions. No fix yet Fix from $4,9002026-08-20 MEDIUM 6.5 CVE-2026-66601 Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions. No fix yet Fix from $4,0002026-08-20 CRITICAL 9.1 CVE-2026-66600 Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. No fix yet Fix from $5,7502026-08-20 HIGH 7.1 CVE-2026-66598 Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. No fix yet Fix from $4,9002026-08-20 HIGH 7.1 CVE-2026-66597 Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions. No fix yet Fix from $4,9002026-08-20 MEDIUM 5.9 CVE-2026-66595 Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions. No fix yet Fix from $4,0002026-08-20 HIGH 8.5 CVE-2026-66594 Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. No fix yet Fix from $4,9002026-08-20 CRITICAL 9.3 CVE-2026-66593 Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-66592 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. No fix yet Fix from $5,7502026-08-20 HIGH 7.1 CVE-2026-66590 Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. No fix yet Fix from $4,9002026-08-20 MEDIUM 6.6 CVE-2026-66586 Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions. No fix yet Fix from $4,0002026-08-20 CRITICAL 9.8 CVE-2026-66583 Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. No fix yet Fix from $5,7502026-08-20 HIGH 7.1 CVE-2026-66582 Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. No fix yet Fix from $4,9002026-08-20 HIGH 7.1 CVE-2026-66581 Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. No fix yet Fix from $4,9002026-08-20 HIGH 8.1 CVE-2026-28150 Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. No fix yet Fix from $4,9002026-08-20 MEDIUM 5.4 CVE-2025-62307 HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, an… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.5 CVE-2025-53999 Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. No fix yet Fix from $4,0002026-08-20 CRITICAL 9.8 CVE-2025-15689 Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2025-15688 Unauthenticated SQL Injection in Capella <= 2.5.5 versions. No fix yet Fix from $5,7502026-08-20 HIGH 8.1 CVE-2025-15637 Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. No fix yet Fix from $4,9002026-08-20 MEDIUM 5.0 CVE-2026-77067 The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file im… Patch available Fix from $4,0002026-08-20 MEDIUM 5.0 CVE-2026-77066 The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig(… Patch available Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-77026 Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforc… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.5 CVE-2026-73199 A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending … No fix yet Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-73198 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitr… No fix yet Fix from $4,9002026-08-20 HIGH 7.5 CVE-2026-73197 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/m… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.1 CVE-2026-13097 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.6 CVE-2026-11861 A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti… No fix yet Fix from $5,7502026-08-20 HIGH 7.8 CVE-2026-18917 A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla… No fix yet Fix from $4,9002026-08-20