Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-32469 Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-28180 Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 5.9 CVE-2026-28179 Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-28178 Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions. No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-28177 Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-28172 Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-28169 Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-28146 Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. No fix yet Fix from $1,6002026-08-06 HIGH 7.1 CVE-2026-28143 Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-28141 Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-28140 Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-28139 Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. No fix yet Fix from $2,3002026-08-06 HIGH 8.8 CVE-2026-28111 Contributor Privilege Escalation in Forminator <= 1.56.0 versions. No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-28082 Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-28005 Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. No fix yet Fix from $2,3002026-08-06 MEDIUM 6.5 CVE-2026-25403 Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-19045 A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-19044 A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-5134 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C… No fix yet Fix from $2,3002026-08-06 HIGH 8.3 CVE-2026-16731 OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may … No fix yet Fix from $1,9502026-08-06 HIGH 8.7 CVE-2026-16315 OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may … No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-65551 Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-19039 A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of t… No fix yet Fix from $1,6002026-08-06 HIGH 7.2 CVE-2026-19036 A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulatio… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-0673 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via t… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.4 CVE-2026-8166 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pu… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.4 CVE-2026-5391 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' … No fix yet Fix from $1,6002026-08-06 MEDIUM 6.4 CVE-2026-5158 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… No fix yet Fix from $1,6002026-08-06 HIGH 7.2 CVE-2026-19035 A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The m… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-11983 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du… No fix yet Fix from $1,6002026-08-06