Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-15338

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via th…

No fix yet
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-15073

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-15072

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 8.8
CVE-2026-13353

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all vers…

No fix yet
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-13262

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val'…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.2
CVE-2026-13114

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and Us…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 5.3
CVE-2026-12426

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 8.8
CVE-2026-13756

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing au…

Mitigation only
Fix from $1,950 2026-07-11
Unclassified MEDIUM 6.5
CVE-2026-11426

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to th…

Mitigation only
Fix from $1,600 2026-07-11
Unclassified HIGH 7.5
CVE-2026-44383

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of m…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-42952

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-15089

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

No fix yet
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.9
CVE-2026-15087

vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.

No fix yet
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.9
CVE-2026-15086

vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.

No fix yet
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-20744

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.9
CVE-2026-14480

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application store…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.9
CVE-2026-11915

vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.

No fix yet
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.9
CVE-2026-11914

vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.

No fix yet
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-11913

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

No fix yet
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-47422

Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and t…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-57807

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Cli…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.1
CVE-2026-55880

OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the owners…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-13039

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-12761

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to …

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-11321

The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, wi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.8
CVE-2026-6212

Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue aff…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-5801

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.9
CVE-2026-15146

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP se…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-2397

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.8
CVE-2026-55885

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the …

Mitigation only
Fix from $1,600 2026-07-10