Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-50644 SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands int… Mitigation only Fix from $1,9502026-07-09 HIGH 8.8 CVE-2026-4275 The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.5 CVE-2026-12428 The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values()… Mitigation only Fix from $1,6002026-07-09 HIGH 7.1 CVE-2026-14372 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file d… Mitigation only Fix from $1,9502026-07-09 HIGH 7.2 CVE-2026-13441 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_back… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.1 CVE-2026-5793 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticare… Mitigation only Fix from $1,6002026-07-09 CRITICAL 9.8 CVE-2026-5955 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticare… Mitigation only Fix from $2,3002026-07-09 MEDIUM 6.5 CVE-2026-1365 Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affe… No fix yet Fix from $1,6002026-07-09 CRITICAL 9.3 CVE-2026-2342 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp al… Mitigation only Fix from $2,3002026-07-09 HIGH 7.5 CVE-2026-1989 Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Id… Mitigation only Fix from $1,9502026-07-09 CRITICAL 9.8 CVE-2026-15158 The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachmen… Mitigation only Fix from $2,3002026-07-09 MEDIUM 6.5 CVE-2026-8996 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, … Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-7558 The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and in… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.4 CVE-2026-6910 The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `h… Mitigation only Fix from $1,6002026-07-09 HIGH 7.2 CVE-2026-8848 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorizatio… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.4 CVE-2026-4653 The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up t… Mitigation only Fix from $1,6002026-07-09 HIGH 8.1 CVE-2026-31985 When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verificat… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.4 CVE-2026-14343 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all… Mitigation only Fix from $1,6002026-07-09 HIGH 7.2 CVE-2026-15000 The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all ve… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.4 CVE-2026-13771 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all version… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-13450 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.1 CVE-2026-13334 The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including,… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.4 CVE-2026-13253 The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/ad… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.6 CVE-2026-13080 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all ver… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-13011 The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-12418 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecur… Mitigation only Fix from $1,6002026-07-09 CRITICAL 9.8 CVE-2026-14245 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Acc… Mitigation only Fix from $2,3002026-07-09 MEDIUM 5.3 CVE-2026-12406 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authori… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.4 CVE-2026-12170 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Sit… Mitigation only Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-47840 A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harves… Mitigation only Fix from $1,9502026-07-09