Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-16950 The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing u… No fix yet Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-16617 The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public fi… No fix yet Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-16616 The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, a… No fix yet Fix from $4,9002026-08-19 HIGH 7.1 CVE-2026-16570 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on on… No fix yet Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-16058 The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers… No fix yet Fix from $4,0002026-08-19 MEDIUM 6.8 CVE-2026-15253 The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in t… No fix yet Fix from $4,0002026-08-19 HIGH 7.5 CVE-2026-14861 The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to a… No fix yet Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-14334 The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthentica… No fix yet Fix from $4,9002026-08-19 MEDIUM 6.5 CVE-2026-13175 The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with… No fix yet Fix from $4,0002026-08-19 HIGH 7.2 CVE-2026-13174 The Eventin WordPress plugin before 4.1.21 does not verify ownership or capability before deleting user accounts, allowing users with contributor-le… No fix yet Fix from $4,9002026-08-19 HIGH 8.1 CVE-2026-13169 The Eventin WordPress plugin before 4.1.21 does not properly verify ownership of events before allowing them to be modified, deleted, or reassigned … No fix yet Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-12983 The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowing unauthenticated users to p… No fix yet Fix from $4,9002026-08-19 HIGH 8.5 CVE-2026-11565 The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing… No fix yet Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-70408 An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. No fix yet Fix from $4,9002026-08-19 MEDIUM 6.1 CVE-2026-66358 A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. No fix yet Fix from $4,0002026-08-19 HIGH 8.1 CVE-2026-19942 The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary fil… No fix yet Fix from $4,9002026-08-19 HIGH 7.3 CVE-2026-76050 A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?acti… No fix yet Fix from $4,9002026-08-19 HIGH 7.3 CVE-2026-76049 A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php… No fix yet Fix from $4,9002026-08-19 HIGH 7.3 CVE-2026-76048 A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.p… No fix yet Fix from $4,9002026-08-19 CRITICAL 10.0 CVE-2026-76008 A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P… No fix yet Fix from $5,7502026-08-19 CRITICAL 9.9 CVE-2026-76004 A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of th… No fix yet Fix from $5,7502026-08-19 CRITICAL 9.9 CVE-2026-76003 A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing… No fix yet Fix from $5,7502026-08-19 HIGH 7.3 CVE-2026-75987 A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/sc… No fix yet Fix from $4,9002026-08-19 HIGH 7.3 CVE-2026-75986 A vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of… No fix yet Fix from $4,9002026-08-19 HIGH 7.4 CVE-2026-75985 A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/ping.cgi. This manipulation of t… No fix yet Fix from $4,9002026-08-19 MEDIUM 6.4 CVE-2026-15421 The Speed Optimizer – The All-In-One Performance-Boosting Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Image Tag Attr… No fix yet Fix from $4,0002026-08-19 CRITICAL 9.1 CVE-2026-11751 A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allow… No fix yet Fix from $5,7502026-08-19 HIGH 7.4 CVE-2026-75984 A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admin.cgi. The manipulation of th… No fix yet Fix from $4,9002026-08-19 MEDIUM 6.3 CVE-2026-75979 A vulnerability was found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected is the function execSqlText/previewSqlText of the file DesignerCo… No fix yet Fix from $4,0002026-08-19 MEDIUM 6.3 CVE-2026-75978 A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController… No fix yet Fix from $4,0002026-08-19