Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-15338 The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via th… No fix yet Fix from $1,9502026-07-11 MEDIUM 6.5 CVE-2026-15073 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al… Mitigation only Fix from $1,6002026-07-11 MEDIUM 6.5 CVE-2026-15072 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in al… Mitigation only Fix from $1,6002026-07-11 HIGH 8.8 CVE-2026-13353 The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all vers… No fix yet Fix from $1,9502026-07-11 MEDIUM 6.5 CVE-2026-13262 The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val'… Mitigation only Fix from $1,6002026-07-11 HIGH 7.2 CVE-2026-13114 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and Us… Mitigation only Fix from $1,9502026-07-11 MEDIUM 5.3 CVE-2026-12426 The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… Mitigation only Fix from $1,6002026-07-11 HIGH 8.8 CVE-2026-13756 The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing au… Mitigation only Fix from $1,9502026-07-11 MEDIUM 6.5 CVE-2026-11426 The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to th… Mitigation only Fix from $1,6002026-07-11 HIGH 7.5 CVE-2026-44383 Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of m… Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-42952 Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.1 CVE-2026-15089 vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. No fix yet Fix from $2,3002026-07-10 MEDIUM 5.9 CVE-2026-15087 vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*. No fix yet Fix from $1,6002026-07-10 MEDIUM 5.9 CVE-2026-15086 vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*. No fix yet Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-20744 The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.9 CVE-2026-14480 OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application store… Mitigation only Fix from $2,3002026-07-10 MEDIUM 5.9 CVE-2026-11915 vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*. No fix yet Fix from $1,6002026-07-10 MEDIUM 5.9 CVE-2026-11914 vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*. No fix yet Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-11913 vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. No fix yet Fix from $2,3002026-07-10 MEDIUM 5.3 CVE-2026-47422 Frappe is a full-stack web application framework. Prior to 15.107.5 and 16.18.2, an endpoint in reportview lacked appropriate permission checks and t… Mitigation only Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-57807 Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Cli… Mitigation only Fix from $2,3002026-07-10 HIGH 7.1 CVE-2026-55880 OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran their SQL without the owners… Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-13039 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass due to a … Mitigation only Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-12761 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to … Mitigation only Fix from $2,3002026-07-10 MEDIUM 6.4 CVE-2026-11321 The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, wi… Mitigation only Fix from $1,6002026-07-10 HIGH 8.8 CVE-2026-6212 Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue aff… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.8 CVE-2026-5801 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt… Mitigation only Fix from $2,3002026-07-10 MEDIUM 5.9 CVE-2026-15146 GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP se… Mitigation only Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-2397 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows… Mitigation only Fix from $2,3002026-07-10 MEDIUM 6.8 CVE-2026-55885 Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the … Mitigation only Fix from $1,6002026-07-10