Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-14207 The LifterLMS WordPress plugin before 10.0.10 does not strip event-handler attributes from a course pricing field before storing and rendering it, a… No fix yet Fix from $1,6002026-07-30 HIGH 8.6 CVE-2026-13395 The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a user-supplied parameter from … No fix yet Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-13345 The Essential Addons for Elementor WordPress plugin before 6.6.10 does not perform authorization, status, or visibility checks when resolving WooCom… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2026-13330 The Animation Addons for Elementor WordPress plugin before 2.7.0 does not sanitise uploaded SVG/SVGZ files, which it adds to the list of allowed upl… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-13178 The Eventin WordPress plugin before 4.1.16 does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauth… No fix yet Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-13143 The WP Travel WordPress plugin before 11.8.1 does not verify PayPal Instant Payment Notifications through the PayPal post-back handshake before mark… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-12687 The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into through its front-end registrat… No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-12500 The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress … No fix yet Fix from $1,9502026-07-30 MEDIUM 6.1 CVE-2026-11881 The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration settings before outputting it inside… No fix yet Fix from $1,6002026-07-30 MEDIUM 5.4 CVE-2026-11870 The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-11867 The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term creation, modification, and d… No fix yet Fix from $1,6002026-07-30 MEDIUM 5.9 CVE-2026-11782 The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update actio… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-1360 The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-16610 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via… No fix yet Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-14356 The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin … Mitigation only Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-1982 The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is d… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-16092 The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action… No fix yet Fix from $1,6002026-07-30 HIGH 7.3 CVE-2026-16727 Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbi… No fix yet Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-15929 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection.… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.6 CVE-2026-17713 Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had comp… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.6 CVE-2026-17701 Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the … No fix yet Fix from $2,3002026-07-30 MEDIUM 5.1 CVE-2026-62946 ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, proc… No fix yet Fix from $1,6002026-07-30 HIGH 7.3 CVE-2025-69949 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email. No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-69945 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-69944 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter. No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2025-69943 kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid. Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2025-69942 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. No fix yet Fix from $2,3002026-07-29 HIGH 7.3 CVE-2025-67408 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status. No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-67407 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class. No fix yet Fix from $1,9502026-07-29 HIGH 7.3 CVE-2025-67406 https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). T… No fix yet Fix from $1,9502026-07-29