Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-32469

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-28180

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.9
CVE-2026-28179

Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-28178

Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28177

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28172

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-28169

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-28146

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28143

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28141

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-28140

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.8
CVE-2026-28111

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28082

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28005

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-25403

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19045

A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19044

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.3
CVE-2026-16731

OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may …

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.7
CVE-2026-16315

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may …

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-65551

Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19039

A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of t…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.2
CVE-2026-19036

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulatio…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-0673

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via t…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-8166

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pu…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-5391

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' …

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-5158

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.2
CVE-2026-19035

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The m…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-11983

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du…

No fix yet
Fix from $1,600 2026-08-06