Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-66639 Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66638 Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66637 Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-66636 Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions. No fix yet Fix from $4,0002026-08-18 HIGH 7.4 CVE-2026-66635 Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-66633 Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-66629 Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions. No fix yet Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-66627 Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. No fix yet Fix from $5,7502026-08-18 HIGH 7.5 CVE-2026-66622 Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-66621 Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.2 CVE-2026-66620 Editor PHP Object Injection in OptionTree <= 2.7.3 versions. No fix yet Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-61407 Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attack… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-59940 Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all… No fix yet Fix from $5,7502026-08-18 MEDIUM 5.9 CVE-2026-50139 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the… No fix yet Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-50138 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `-… No fix yet Fix from $4,9002026-08-18 HIGH 7.2 CVE-2026-32553 Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-32549 Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-32547 Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-32481 Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. No fix yet Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-32474 Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. No fix yet Fix from $5,7502026-08-18 HIGH 7.2 CVE-2026-32473 Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-32472 Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-32470 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. No fix yet Fix from $5,7502026-08-18 HIGH 7.4 CVE-2026-18534 ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to i… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-32468 Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. No fix yet Fix from $4,9002026-08-18 MEDIUM 6.0 CVE-2026-32467 Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. No fix yet Fix from $4,0002026-08-18 HIGH 8.5 CVE-2026-32466 Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. No fix yet Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-32465 Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. No fix yet Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-32464 Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. No fix yet Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-32463 Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. No fix yet Fix from $5,7502026-08-18