Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-57394 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-57393 Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoic… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57392 Missing Authorization vulnerability in Themefic Tourfic tourfic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57391 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57390 Missing Authorization vulnerability in EDGARROJAS Extra Product Options Builder for WooCommerce additional-product-fields-for-woocommerce allows Expl… Mitigation only Fix from $1,6002026-07-13 HIGH 8.6 CVE-2026-57389 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg groundhogg allows Path Traver… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57388 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Hydra Booking hydra-booking allows Sto… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57387 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in picu picu picu allows Stored XSS.This issue aff… Mitigation only Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-57386 Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through … No fix yet Fix from $1,9502026-07-13 HIGH 8.5 CVE-2026-57385 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL In… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57383 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Stored XSS… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57382 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-li… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57381 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows … Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57380 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions for Leaflet Map extensions-le… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Sto… Mitigation only Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-57378 Missing Authorization vulnerability in Phil Kurth Advanced Forms advanced-forms allows Exploiting Incorrectly Configured Access Control Security Leve… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-57377 Missing Authorization vulnerability in WPXPO WowAddons product-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This is… Mitigation only Fix from $1,6002026-07-13 HIGH 7.1 CVE-2026-57376 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader ElementInvader Addons for Eleme… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-57375 Missing Authorization vulnerability in FluxBuilder MStore API mstore-api allows Exploiting Incorrectly Configured Access Control Security Levels.This… Mitigation only Fix from $1,6002026-07-13 HIGH 7.2 CVE-2026-57372 Server-Side Request Forgery (SSRF) vulnerability in denishua WPJAM Basic wpjam-basic allows Server Side Request Forgery.This issue affects WPJAM Basi… No fix yet Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-57371 Deserialization of Untrusted Data vulnerability in denishua WPJAM Basic wpjam-basic allows Object Injection.This issue affects WPJAM Basic: from n/a … Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57369 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Builder themify-builder allow… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-57368 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Jobmonster noo-jobmonster allows Refle… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-57365 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hitesh Chandwani reCAPTCHA (v2 & v3) for As… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-57364 Improper Validation of Specified Quantity in Input vulnerability in WPDeveloper Better Payment – Instant Payments, Donations, Fundraising with Subscr… Mitigation only Fix from $1,6002026-07-13 HIGH 7.1 CVE-2026-57363 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.3 CVE-2026-22103 The NPC start endpoint on the web server at port 8090 is vulnerable to command injection. Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.3 CVE-2026-22102 A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in… Mitigation only Fix from $2,3002026-07-13 HIGH 8.6 CVE-2026-22100 The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be execute… Mitigation only Fix from $1,9502026-07-13 HIGH 8.7 CVE-2026-22099 The charging station does not require authentication for Bluetooth commands to perform actions. The functionality exposed includes sensitive informat… Mitigation only Fix from $1,9502026-07-13