Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-13767 The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.4 CVE-2026-13755 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-13754 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, a… No fix yet Fix from $1,6002026-07-16 HIGH 8.8 CVE-2026-13741 The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,… Mitigation only Fix from $1,9502026-07-16 CRITICAL 9.2 CVE-2026-15925 Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacke… No fix yet Fix from $2,3002026-07-16 MEDIUM 5.5 CVE-2026-12979 The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, all… No fix yet Fix from $1,6002026-07-16 HIGH 7.1 CVE-2026-12978 The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its p… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.1 CVE-2026-12869 The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-12684 The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media… No fix yet Fix from $1,6002026-07-16 HIGH 8.1 CVE-2026-12585 The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the … No fix yet Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-12525 The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing … No fix yet Fix from $1,9502026-07-16 MEDIUM 5.9 CVE-2026-12510 The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, al… No fix yet Fix from $1,6002026-07-16 CRITICAL 9.8 CVE-2026-12492 The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authent… No fix yet Fix from $2,3002026-07-16 MEDIUM 6.5 CVE-2026-12395 The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authentic… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.4 CVE-2026-11866 The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.1 CVE-2026-11371 The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the featu… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.1 CVE-2026-15306 The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via … No fix yet Fix from $1,6002026-07-16 CRITICAL 9.8 CVE-2026-15013 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version… No fix yet Fix from $2,3002026-07-16 HIGH 7.2 CVE-2026-13042 The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 … No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-21729 Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strat… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.4 CVE-2026-15652 The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Blo… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.4 CVE-2026-14987 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-12941 The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'orde… No fix yet Fix from $1,6002026-07-16 HIGH 7.5 CVE-2026-12753 The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' p… No fix yet Fix from $1,9502026-07-16 HIGH 7.8 CVE-2026-3842 A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This o… No fix yet Fix from $1,9502026-07-16 HIGH 8.1 CVE-2026-1609 A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak f… Build Of Keycloak No fix yet Fix from $1,9502026-07-16 MEDIUM 6.3 CVE-2026-15909 A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the fil… No fix yet Fix from $1,6002026-07-16 HIGH 7.3 CVE-2026-15907 A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Exe… No fix yet Fix from $1,9502026-07-16 HIGH 7.7 CVE-2026-45313 Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc… Mitigation only Fix from $1,9502026-07-15 HIGH 7.5 CVE-2026-36590 An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component Nanomq Mitigation only Fix from $1,9502026-07-15