Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-15963

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15726

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and inclu…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.3
CVE-2026-15441

The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15066

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and includ…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.1
CVE-2026-15009

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.2
CVE-2026-15002

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 v…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-14524

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDe…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 8.8
CVE-2026-14498

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' paramet…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-13358

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-11780

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_tit…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.3
CVE-2026-19926

A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-ga…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-19924

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19923

A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19921

A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /h…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19920

A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulatio…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.3
CVE-2026-19919

A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19918

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19917

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. …

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.5
CVE-2026-73054

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parame…

No fix yet
Fix from $4,900 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73053

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73052

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73050

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu…

No fix yet
Fix from $5,750 2026-08-15
Unclassified MEDIUM 6.2
CVE-2026-73047

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature …

No fix yet
Fix from $4,000 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-73046

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, whic…

No fix yet
Fix from $5,750 2026-08-15
Unclassified HIGH 7.5
CVE-2026-73045

SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that al…

No fix yet
Fix from $4,900 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73044

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attribu…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73043

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go temp…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73042

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open …

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73041

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject ma…

No fix yet
Fix from $5,750 2026-08-15
Unclassified HIGH 7.3
CVE-2026-19905

A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx…

No fix yet
Fix from $4,900 2026-08-15