Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.1
CVE-2026-14207

The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, a…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.6
CVE-2026-13395

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from …

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-13345

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCom…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2026-13330

The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upl…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-13178

The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauth…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-13143

The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before mark…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-12687

The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registrat…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-12500

The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress …

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.1
CVE-2026-11881

The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.4
CVE-2026-11870

The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-11867

The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and d…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.9
CVE-2026-11782

The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update actio…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-1360

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th…

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via…

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 8.8
CVE-2026-14356

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin …

Mitigation only
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-1982

The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is d…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-16092

The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.3
CVE-2026-16727

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbi…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.1
CVE-2026-15929

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection.…

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.6
CVE-2026-17713

Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had comp…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.6
CVE-2026-17701

Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the …

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.1
CVE-2026-62946

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, proc…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.3
CVE-2025-69949

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-69945

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-69944

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-69943

kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-69942

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67408

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67407

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.3
CVE-2025-67406

https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). T…

No fix yet
Fix from $1,950 2026-07-29