Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2026-15066 The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and includ… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.1 CVE-2026-15009 The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site… No fix yet Fix from $4,0002026-08-16 HIGH 7.2 CVE-2026-15002 The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 v… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.1 CVE-2026-14524 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDe… No fix yet Fix from $5,7502026-08-16 HIGH 8.8 CVE-2026-14498 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' paramet… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.5 CVE-2026-13358 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-11780 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_tit… No fix yet Fix from $4,0002026-08-16 HIGH 7.3 CVE-2026-19926 A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-ga… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.8 CVE-2026-19924 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th… No fix yet Fix from $5,7502026-08-16 MEDIUM 6.3 CVE-2026-19923 A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19921 A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /h… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19920 A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulatio… No fix yet Fix from $4,0002026-08-16 HIGH 7.3 CVE-2026-19919 A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.3 CVE-2026-19918 A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19917 A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. … No fix yet Fix from $4,0002026-08-15 HIGH 7.5 CVE-2026-73054 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parame… No fix yet Fix from $4,9002026-08-15 CRITICAL 9.0 CVE-2026-73053 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73052 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73050 SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu… No fix yet Fix from $5,7502026-08-15 MEDIUM 6.2 CVE-2026-73047 siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature … No fix yet Fix from $4,0002026-08-15 CRITICAL 9.8 CVE-2026-73046 SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, whic… No fix yet Fix from $5,7502026-08-15 HIGH 7.5 CVE-2026-73045 SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that al… No fix yet Fix from $4,9002026-08-15 CRITICAL 9.0 CVE-2026-73044 SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attribu… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73043 SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go temp… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73042 SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open … No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73041 SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject ma… No fix yet Fix from $5,7502026-08-15 HIGH 7.3 CVE-2026-19905 A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx… No fix yet Fix from $4,9002026-08-15 CRITICAL 9.1 CVE-2026-18855 The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields … No fix yet Fix from $5,7502026-08-15 MEDIUM 5.3 CVE-2026-19903 A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the componen… No fix yet Fix from $4,0002026-08-15 HIGH 8.1 CVE-2026-19901 A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipula… No fix yet Fix from $4,9002026-08-15