Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Build Of Keycloak HIGH 8.1
CVE-2026-18967

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.2
CVE-2026-18510

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment C…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-18400

The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'd…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-18395

The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-18050

The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads,…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-16954

The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, …

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-16734

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by t…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-16537

The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, al…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-16290

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the hand…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.2
CVE-2026-16268

The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-16065

The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL st…

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-16054

The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid no…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.2
CVE-2026-14829

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-14547

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its p…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-14314

The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced …

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-14313

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-wooco…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-14240

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory wi…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-14204

The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a lo…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-13703

The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any l…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-13154

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before queryin…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-13153

The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-12713

The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowin…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.1
CVE-2026-11588

The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisat…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.1
CVE-2025-15678

The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Autho…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.3
CVE-2026-19000

A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component An…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-18998

A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.t…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-18997

A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.1
CVE-2026-15459

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet conn…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-18996

A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCo…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-18992

A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/exec…

No fix yet
Fix from $1,600 2026-08-06