Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.4
CVE-2026-15016

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scrip…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.8
CVE-2026-4648

Use of an insecure cryptographic algorithm in the cashless payment system using NFC wristbands from CasfID Servicios Tecnológicos S.L.U. (version use…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.3
CVE-2026-21047

Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-16774

The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handle…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-16773

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-15411

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to au…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-15025

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable to Missing Authorization in vers…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.2
CVE-2026-13440

The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for WordPress is vulnerable to St…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-13110

The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 2.1.0. This is due to a mis…

No fix yet
Fix from $1,600 2026-07-28
Unclassified CRITICAL 10.0
CVE-2026-65880

Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code exec…

No fix yet
Fix from $2,300 2026-07-28
Unclassified MEDIUM 5.1
CVE-2026-63303

A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fails to normalize dot-dot-slash…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.1
CVE-2026-63302

Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated attacker with admin privileges …

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.0
CVE-2026-63301

In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding option from the interface; h…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.3
CVE-2026-18029

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status res…

No fix yet
Fix from $1,600 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-16462

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL comm…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 7.5
CVE-2026-14785

The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all versions up to, and including, 1…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-14328

The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all version…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-11841

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to imprope…

Mitigation only
Fix from $2,300 2026-07-28
Unclassified MEDIUM 5.0
CVE-2026-11598

The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all versions up to, and including…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-10207

The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.73. This is due to insufficie…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.8
CVE-2026-9680

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to …

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.1
CVE-2026-8167

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solutions News Theme V8 allows Re…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.2
CVE-2026-61376

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exp…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.2
CVE-2026-59764

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an …

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.2
CVE-2026-44387

ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is explo…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-15267

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL Injection via the 'wppm_proj_…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-14516

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injection via the 'staff_ids' para…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.1
CVE-2026-14171

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website.…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.1
CVE-2026-14169

Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites existing u…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-14168

A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of the configuration table resulti…

Mitigation only
Fix from $1,950 2026-07-28