Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-18216

The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administe…

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.5
CVE-2026-16611

The Product Feed PRO for WooCommerce by AdTribes WordPress plugin before 13.5.7 does not perform an authorization check on one of its REST read rout…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-16541

The Simply Schedule Appointments WordPress plugin before 1.6.12.17 does not restrict the user records returned by some of its REST endpoints to those…

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.1
CVE-2026-16007

AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 5.4
CVE-2026-14230

The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJAX handlers (gated only by a …

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-14229

The ECS WordPress plugin before 4.3.8 does not check the post status or any capability when rendering an Elementor document requested through one of…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-18387

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'tag_query' parameter…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.4
CVE-2026-17090

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Button Module '…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-16586

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via Mul…

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.2
CVE-2026-16145

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ac…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-15993

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via '{username}'…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.4
CVE-2026-15948

The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' …

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-15453

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in…

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 7.2
CVE-2026-13360

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' param…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-8840

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2…

No fix yet
Fix from $4,000 2026-08-15
Unclassified MEDIUM 6.5
CVE-2026-16080

The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' parameter in all versions up to, and …

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 8.8
CVE-2026-15965

The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up t…

No fix yet
Fix from $4,900 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-15341

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and incl…

No fix yet
Fix from $5,750 2026-08-15
Unclassified HIGH 8.8
CVE-2026-15312

The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, …

No fix yet
Fix from $4,900 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-15303

The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_sto…

No fix yet
Fix from $5,750 2026-08-15
Unclassified HIGH 7.5
CVE-2026-15162

The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-s…

No fix yet
Fix from $4,900 2026-08-15
Unclassified HIGH 8.8
CVE-2026-15001

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.7…

No fix yet
Fix from $4,900 2026-08-15
Unclassified CRITICAL 9.1
CVE-2026-14484

The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file pat…

No fix yet
Fix from $5,750 2026-08-15
Unclassified HIGH 7.2
CVE-2026-14433

The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_i…

No fix yet
Fix from $4,900 2026-08-15
Unclassified MEDIUM 5.3
CVE-2026-12128

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to,…

No fix yet
Fix from $4,000 2026-08-15
Openshift Update Service HIGH 7.1
CVE-2026-74247

A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SS…

No fix yet
Fix from $4,900 2026-08-14
Openshift Update Service MEDIUM 6.5
CVE-2026-74241

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned d…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-74250

In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the au…

No fix yet
Fix from $4,000 2026-08-14
Openshift Update Service HIGH 7.5
CVE-2026-74245

A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs withou…

No fix yet
Fix from $4,900 2026-08-14
Openshift Update Service HIGH 7.5
CVE-2026-74244

A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by s…

No fix yet
Fix from $4,900 2026-08-14