Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-56030 Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. Mitigation only Fix from $2,3002026-06-26 HIGH 7.5 CVE-2026-56029 Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions. Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.8 CVE-2026-56028 Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-56027 Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. Mitigation only Fix from $2,3002026-06-26 MEDIUM 6.4 CVE-2026-56026 Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-56025 Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.1 CVE-2026-56011 Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-56010 Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 8.8 CVE-2026-56008 Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54847 Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54846 Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.3 CVE-2026-54840 Unauthenticated Broken Access Control in Newsletters <= 4.13 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54839 Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2.0.9 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54837 Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54835 Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54834 Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.4 CVE-2026-54833 Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-54832 Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions. Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.3 CVE-2026-54831 Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54827 Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. Mitigation only Fix from $2,3002026-06-26 HIGH 7.6 CVE-2026-54826 Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions. Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.3 CVE-2026-54825 Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. Mitigation only Fix from $2,3002026-06-26 HIGH 7.5 CVE-2026-54824 Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions. Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.3 CVE-2026-54820 Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. Mitigation only Fix from $2,3002026-06-26 MEDIUM 6.5 CVE-2026-52701 Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions. No fix yet Fix from $1,6002026-06-26 HIGH 7.8 CVE-2026-45257 The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumpti… FreeBSD Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.5 CVE-2026-45256 When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not ch… FreeBSD Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-30041 An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-30040 A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the c… Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2026-24547 Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. Mitigation only Fix from $1,6002026-06-26