Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.4
CVE-2026-15464

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to,…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15334

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15333

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-12654

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. Th…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 7.5
CVE-2026-14603

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated us…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.8
CVE-2026-14172

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, al…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.5
CVE-2026-12981

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthentica…

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.1
CVE-2026-12877

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it…

No fix yet
Fix from $2,300 2026-07-24
Unclassified MEDIUM 5.4
CVE-2026-12689

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions,…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-12688

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthentic…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 7.5
CVE-2026-12497

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not …

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.8
CVE-2026-16870

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.2
CVE-2026-66138

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-54422

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the cre…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-6454

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to i…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15100

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all …

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-13464

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.0
CVE-2026-12736

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::sa…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-11354

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the …

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2025-9205

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficien…

No fix yet
Fix from $1,600 2026-07-24
Azure Key Vault CRITICAL 9.8
CVE-2026-62825

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Dns CRITICAL 9.8
CVE-2026-58275

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Exchange Online CRITICAL 10.0
CVE-2026-56191

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Ai Search HIGH 8.8
CVE-2026-56167

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-24
Account CRITICAL 9.8
CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Red Hat Openshift CRITICAL 9.9
CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Surface Management Services HIGH 8.8
CVE-2026-54120

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24
365 Copilot CRITICAL 9.9
CVE-2026-50517

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
Graph MEDIUM 6.5
CVE-2026-49159

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-07-24
Azure Api Management HIGH 7.2
CVE-2026-35425

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24