Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.6
CVE-2026-10540

The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified CRITICAL 9.0
CVE-2026-10539

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified HIGH 8.0
CVE-2026-10538

Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-1239

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing aut…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-14193

DVP80ES300T with Improper Validation of Array Index Vulnerability

No fix yet
Fix from $1,950 2026-07-01
Unclassified HIGH 7.4
CVE-2026-12579

AS228T with Authentication Bypass Vulnerability

No fix yet
Fix from $1,950 2026-07-01
Unclassified HIGH 7.2
CVE-2026-11883

The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-11823

The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.1
CVE-2026-11794

The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it create…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-11568

The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCo…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.1
CVE-2026-10750

The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowin…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.3
CVE-2025-15666

A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function Assimp::Sc…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-9107

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.2
CVE-2026-7517

The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' param…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.1
CVE-2026-6070

The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-2387

The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to th…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.2
CVE-2026-13731

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conv…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-13468

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to,…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-13443

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-13246

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.1
CVE-2026-13015

The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, …

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-12923

The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-12135

The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute i…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-12127

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutrali…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-12110

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'ta…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-12090

The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wp…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-11988

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in al…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-11380

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.7
CVE-2026-20463

In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious ac…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.7
CVE-2026-20462

In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious ac…

Mitigation only
Fix from $1,600 2026-07-01