Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.6
CVE-2026-61426

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthe…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified HIGH 7.5
CVE-2026-56303

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and ex…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-56296

Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages …

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 8.8
CVE-2026-1359

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Mitigation only
Fix from $1,950 2026-07-11
Unclassified HIGH 7.5
CVE-2026-9282

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources functio…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-9017

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.2
CVE-2026-6939

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all …

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-6801

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.5
CVE-2026-4661

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname…

No fix yet
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-1382

The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 8.8
CVE-2026-15155

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via E…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-15010

The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Addit…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-12994

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. …

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-12126

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-11901

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-10865

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 8.8
CVE-2025-6784

The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortco…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified HIGH 8.1
CVE-2026-7655

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to …

Mitigation only
Fix from $1,950 2026-07-11
Unclassified HIGH 7.2
CVE-2026-13378

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all ve…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-6804

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12.…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-6803

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.2
CVE-2026-3576

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all version…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified HIGH 8.8
CVE-2026-2354

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_exten…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified HIGH 7.5
CVE-2026-15335

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and inclu…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-15097

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, …

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-15096

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 8.8
CVE-2026-14262

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation i…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-13250

The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin no…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2025-13968

The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboar…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.4
CVE-2026-5743

The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and…

Mitigation only
Fix from $1,600 2026-07-11