Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2026-15464 The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to,… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15334 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15333 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros… No fix yet Fix from $1,6002026-07-24 MEDIUM 5.3 CVE-2026-12654 The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. Th… No fix yet Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-14603 The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated us… No fix yet Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-14172 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, al… No fix yet Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-12981 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthentica… No fix yet Fix from $1,9502026-07-24 CRITICAL 9.1 CVE-2026-12877 The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it… No fix yet Fix from $2,3002026-07-24 MEDIUM 5.4 CVE-2026-12689 The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions,… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.5 CVE-2026-12688 The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthentic… No fix yet Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-12497 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not … No fix yet Fix from $1,9502026-07-24 HIGH 8.8 CVE-2026-16870 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati… No fix yet Fix from $1,9502026-07-24 HIGH 7.2 CVE-2026-66138 In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic… No fix yet Fix from $1,9502026-07-24 MEDIUM 5.5 CVE-2026-54422 In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the cre… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-6454 The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to i… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15100 The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all … No fix yet Fix from $1,6002026-07-24 MEDIUM 5.3 CVE-2026-13464 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version… No fix yet Fix from $1,6002026-07-24 HIGH 8.0 CVE-2026-12736 The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::sa… No fix yet Fix from $1,9502026-07-24 MEDIUM 5.3 CVE-2026-11354 The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the … No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2025-9205 The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficien… No fix yet Fix from $1,6002026-07-24 CRITICAL 9.8 CVE-2026-62825 Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. Azure Key Vault No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-58275 Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. Azure Dns No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-56191 Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. Exchange Online No fix yet Fix from $2,3002026-07-24 HIGH 8.8 CVE-2026-56167 Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network. Azure Ai Search No fix yet Fix from $1,9502026-07-24 CRITICAL 9.8 CVE-2026-56165 Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network. Account No fix yet Fix from $2,3002026-07-24 CRITICAL 9.9 CVE-2026-56160 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network. Azure Red Hat Openshift No fix yet Fix from $2,3002026-07-24 HIGH 8.8 CVE-2026-54120 Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. Surface Management Services No fix yet Fix from $1,9502026-07-24 CRITICAL 9.9 CVE-2026-50517 Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. 365 Copilot No fix yet Fix from $2,3002026-07-24 MEDIUM 6.5 CVE-2026-49159 Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. Graph No fix yet Fix from $1,6002026-07-24 HIGH 7.2 CVE-2026-35425 Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. Azure Api Management No fix yet Fix from $1,9502026-07-24