Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-61426 PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthe… Mitigation only Fix from $1,9502026-07-11 HIGH 7.5 CVE-2026-56303 Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and ex… Mitigation only Fix from $1,9502026-07-11 MEDIUM 5.3 CVE-2026-56296 Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages … Mitigation only Fix from $1,6002026-07-11 HIGH 8.8 CVE-2026-1359 The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … Mitigation only Fix from $1,9502026-07-11 HIGH 7.5 CVE-2026-9282 The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources functio… Mitigation only Fix from $1,9502026-07-11 MEDIUM 5.3 CVE-2026-9017 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, … Mitigation only Fix from $1,6002026-07-11 HIGH 7.2 CVE-2026-6939 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all … Mitigation only Fix from $1,9502026-07-11 MEDIUM 5.3 CVE-2026-6801 The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog… Mitigation only Fix from $1,6002026-07-11 HIGH 7.5 CVE-2026-4661 The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname… No fix yet Fix from $1,9502026-07-11 MEDIUM 6.4 CVE-2026-1382 The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and i… Mitigation only Fix from $1,6002026-07-11 HIGH 8.8 CVE-2026-15155 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via E… Mitigation only Fix from $1,9502026-07-11 MEDIUM 6.4 CVE-2026-15010 The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Addit… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-12994 The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. … Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2026-12126 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-11901 The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-10865 The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the… Mitigation only Fix from $1,6002026-07-11 HIGH 8.8 CVE-2025-6784 The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortco… Mitigation only Fix from $1,9502026-07-11 HIGH 8.1 CVE-2026-7655 The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to … Mitigation only Fix from $1,9502026-07-11 HIGH 7.2 CVE-2026-13378 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all ve… Mitigation only Fix from $1,9502026-07-11 MEDIUM 5.3 CVE-2026-6804 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12.… Mitigation only Fix from $1,6002026-07-11 MEDIUM 5.3 CVE-2026-6803 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12… Mitigation only Fix from $1,6002026-07-11 HIGH 7.2 CVE-2026-3576 The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all version… Mitigation only Fix from $1,9502026-07-11 HIGH 8.8 CVE-2026-2354 The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_exten… Mitigation only Fix from $1,9502026-07-11 HIGH 7.5 CVE-2026-15335 The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and inclu… Mitigation only Fix from $1,9502026-07-11 MEDIUM 6.4 CVE-2026-15097 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, … Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2026-15096 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and i… Mitigation only Fix from $1,6002026-07-11 HIGH 8.8 CVE-2026-14262 The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation i… Mitigation only Fix from $1,9502026-07-11 MEDIUM 5.3 CVE-2026-13250 The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin no… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2025-13968 The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboar… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.4 CVE-2026-5743 The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and… Mitigation only Fix from $1,6002026-07-11