Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.6
CVE-2026-16062

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-16064

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when qui…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-16063

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with p…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.5
CVE-2026-15248

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing …

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-15385

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-men…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.5
CVE-2026-15241

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing …

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-15236

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the con…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-15206

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after a…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-15151

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users …

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 8.2
CVE-2026-14920

## Summary

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-14864

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users wit…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.1
CVE-2026-14841

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribu…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.8
CVE-2026-14817

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 8.1
CVE-2026-12586

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CS…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-13389

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthen…

No fix yet
Fix from $1,600 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-8457

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to …

No fix yet
Fix from $2,300 2026-08-02
Unclassified HIGH 7.5
CVE-2026-18352

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' p…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-13339

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_c…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 5.9
CVE-2026-67355

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking coo…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.9
CVE-2026-67354

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.ref…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-67353

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields w…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.6
CVE-2026-67352

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.8
CVE-2026-67343

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retriev…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67342

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67341

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with …

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67340

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor …

Mitigation only
Fix from $2,300 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can cap…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-67337

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.7
CVE-2026-67336

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and …

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-67335

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without …

No fix yet
Fix from $1,600 2026-08-01