Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.6 CVE-2026-10540 The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks… Mitigation only Fix from $1,6002026-07-01 CRITICAL 9.0 CVE-2026-10539 A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow… Mitigation only Fix from $2,3002026-07-01 HIGH 8.0 CVE-2026-10538 Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of … Mitigation only Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-1239 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing aut… Mitigation only Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-14193 DVP80ES300T with Improper Validation of Array Index Vulnerability No fix yet Fix from $1,9502026-07-01 HIGH 7.4 CVE-2026-12579 AS228T with Authentication Bypass Vulnerability No fix yet Fix from $1,9502026-07-01 HIGH 7.2 CVE-2026-11883 The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authentication response, allowing an… Mitigation only Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-11823 The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date' parameter of the bpa_assign… Mitigation only Fix from $1,9502026-07-01 HIGH 8.1 CVE-2026-11794 The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress role assigned when it create… Mitigation only Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-11568 The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status check before returning WooCo… Mitigation only Fix from $1,9502026-07-01 HIGH 8.1 CVE-2026-10750 The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after token authentication, allowin… Mitigation only Fix from $1,9502026-07-01 MEDIUM 5.3 CVE-2025-15666 A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function Assimp::Sc… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-9107 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field… Mitigation only Fix from $1,6002026-07-01 HIGH 7.2 CVE-2026-7517 The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alg_wc_cpg_input_fields' param… Mitigation only Fix from $1,9502026-07-01 CRITICAL 9.1 CVE-2026-6070 The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is… Mitigation only Fix from $2,3002026-07-01 MEDIUM 6.4 CVE-2026-2387 The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.12.9. This is due to th… Mitigation only Fix from $1,6002026-07-01 HIGH 7.2 CVE-2026-13731 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conv… Mitigation only Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-13468 The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to,… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-13443 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Lesson Attachment Title in… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-13246 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'block_id' (and other… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-13015 The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' parameter in versions up to, … Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-12923 The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3. This is due to insufficient… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-12135 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute i… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-12127 The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutrali… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-12110 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'ta… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-12090 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wp… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-11988 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in al… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-11380 The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.7 CVE-2026-20463 In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious ac… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.7 CVE-2026-20462 In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious ac… Mitigation only Fix from $1,6002026-07-01