Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.6
CVE-2026-16950

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing u…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-16617

The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public fi…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.6
CVE-2026-16616

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, a…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.1
CVE-2026-16570

The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on on…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-16058

The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.8
CVE-2026-15253

The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in t…

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 7.5
CVE-2026-14861

The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to a…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-14334

The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthentica…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-13175

The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with…

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 7.2
CVE-2026-13174

The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-le…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.1
CVE-2026-13169

The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned …

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.6
CVE-2026-12983

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to p…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.5
CVE-2026-11565

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-70408

An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges.

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.1
CVE-2026-66358

A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 8.1
CVE-2026-19942

The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary fil…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.3
CVE-2026-76050

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?acti…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.3
CVE-2026-76049

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.3
CVE-2026-76048

A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.p…

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-76008

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76004

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of th…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76003

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.3
CVE-2026-75987

A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/sc…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.3
CVE-2026-75986

A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.4
CVE-2026-75985

A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/ping.cgi. This manipulation of t…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.4
CVE-2026-15421

The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attr…

No fix yet
Fix from $4,000 2026-08-19
Unclassified CRITICAL 9.1
CVE-2026-11751

A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allow…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.4
CVE-2026-75984

A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of th…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.3
CVE-2026-75979

A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerCo…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.3
CVE-2026-75978

A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController…

No fix yet
Fix from $4,000 2026-08-19