Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.4
CVE-2026-15646

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, a…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-15448

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in …

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-15404

The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-15394

The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.3
CVE-2026-15348

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includin…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.8
CVE-2026-15017

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to mi…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15015

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. T…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15011

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, an…

No fix yet
Fix from $2,300 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-14481

The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Script…

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-14282

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to ar…

No fix yet
Fix from $2,300 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-13119

The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by th…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-13009

The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, a…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-52688

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.0
CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 7.8
CVE-2026-16287

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Rese…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.5
CVE-2024-58330

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event d…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.4
CVE-2024-58023

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-9729

The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-9713

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded c…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.4
CVE-2026-9635

The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.1
CVE-2026-59678

An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the net…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.8
CVE-2026-59677

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-own…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.2
CVE-2026-12421

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 6.1
CVE-2026-9066

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.8
CVE-2026-59676

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is run…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-14291

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication cod…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.5
CVE-2026-12082

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated us…

No fix yet
Fix from $1,950 2026-07-23
Linux Kernel HIGH 7.8
CVE-2026-64600

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_h…

Fix: 5.15.212 / 6.1.178+
Fix from $1,950 2026-07-23
Unclassified HIGH 7.2
CVE-2026-7534

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 7.2
CVE-2026-7232

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and inclu…

No fix yet
Fix from $1,950 2026-07-23