Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-14921 The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(), No fix yet Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2026-14919 The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check t… No fix yet Fix from $2,3002026-07-31 MEDIUM 6.1 CVE-2026-14845 The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and … No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-14843 The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an un… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-14834 The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers … No fix yet Fix from $1,6002026-07-31 MEDIUM 6.8 CVE-2026-14833 The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image light… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-14830 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the asso… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-14554 The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing use… No fix yet Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2026-14483 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5… Mitigation only Fix from $2,3002026-07-31 HIGH 7.5 CVE-2026-14333 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and witho… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-14319 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-14317 The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it… No fix yet Fix from $1,6002026-07-31 HIGH 8.8 CVE-2026-13609 The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which rest… Mitigation only Fix from $1,9502026-07-31 HIGH 7.2 CVE-2026-13392 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative cap… No fix yet Fix from $1,9502026-07-31 HIGH 8.6 CVE-2026-12721 The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, al… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-12720 The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users ca… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.4 CVE-2026-12697 The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messag… No fix yet Fix from $1,6002026-07-31 HIGH 8.1 CVE-2026-12695 The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instea… No fix yet Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-12251 The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its regist… No fix yet Fix from $1,9502026-07-31 HIGH 7.1 CVE-2026-55502 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even … No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-43833 Full details and mitigation steps are currently restricted and will be published at a later date. No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-43832 Full details and mitigation steps are currently restricted and will be published at a later date. No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-43831 Full details and mitigation steps are currently restricted and will be published at a later date. No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-43830 Full details and mitigation steps are currently restricted and will be published at a later date. No fix yet Fix from $2,3002026-07-31 HIGH 7.5 CVE-2026-43829 Full details and mitigation steps are currently restricted and will be published at a later date. No fix yet Fix from $1,9502026-07-31 HIGH 7.1 CVE-2026-6890 A use of default credentials vulnerability in the Advantech ECU-1251D allows a remote attacker to gain unauthorised access to the device via SSH usin… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.9 CVE-2026-6889 A denial of service vulnerability in the Advantech ECU-1251D allows a network-adjacent attacker to send a DNP3 signal to the Digital Output address o… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-66720 The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast… No fix yet Fix from $1,6002026-07-30 CRITICAL 9.3 CVE-2026-66421 OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript … No fix yet Fix from $2,3002026-07-30 MEDIUM 6.5 CVE-2026-66369 The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the pro… No fix yet Fix from $1,6002026-07-30