Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-70888 An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component Osslsigncode after 2.10 Fix from $2,3002026-03-25 CRITICAL 9.0 CVE-2026-33749 n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated user with permission to create o… N8n 1.123.27 / 2.13.3+ Fix from $2,3002026-03-25 CRITICAL 9.1 CVE-2026-32573 Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-testing allows Code Injection.Thi… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-32539 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PublishPress PublishPress Revisions revisionary… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-32536 Unrestricted Upload of File with Dangerous Type vulnerability in halfdata Green Downloads halfdata-paypal-green-downloads allows Using Malicious File… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-32525 Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.1 CVE-2026-32524 Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell to a Web Server.This iss… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-32523 Unrestricted Upload of File with Dangerous Type vulnerability in denishua WPJAM Basic wpjam-basic allows Using Malicious Files.This issue affects WPJ… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-32520 Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects Rewards… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.0 CVE-2026-32519 Incorrect Privilege Assignment vulnerability in Bit Apps Bit SMTP bit-smtp allows Privilege Escalation.This issue affects Bit SMTP: from n/a through … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-32512 Deserialization of Untrusted Data vulnerability in Edge-Themes Pelicula pelicula-video-production-and-movie-theme allows Object Injection.This issue … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-32502 Deserialization of Untrusted Data vulnerability in Select-Themes Borgholm borgholm-marketing-agency-theme allows Object Injection.This issue affects … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-32499 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL I… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-32482 Unrestricted Upload of File with Dangerous Type vulnerability in deothemes Ona ona allows Upload a Web Shell to a Web Server.This issue affects Ona: … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-31920 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Devteam HaywoodTech Product Rearrange for WooCo… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-2414 Authorization bypass through User-Controlled key vulnerability in HYPR Server allows Privilege Escalation.This issue affects Server: from 9.5.2 befor… Hypr 10.7.2+ Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27095 Deserialization of Untrusted Data vulnerability in magepeopleteam Bus Ticket Booking with Seat Reservation bus-ticket-booking-with-seat-reservation a… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27084 Deserialization of Untrusted Data vulnerability in ThemeREX Buisson buisson allows Object Injection.This issue affects Buisson: from n/a through <= 1… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27083 Deserialization of Untrusted Data vulnerability in ThemeREX Work & Travel Company work-travel-company allows Object Injection.This issue affects Work… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27082 Deserialization of Untrusted Data vulnerability in ThemeREX Love Story lovestory allows Object Injection.This issue affects Love Story: from n/a thro… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.1 CVE-2026-27071 Missing Authorization vulnerability in Arraytics WPCafe wp-cafe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue af… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27051 Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0. Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-27049 Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobica Core jobica-core allows Authentication Abuse.This issue aff… No fix yet Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-27044 Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.Thi… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.1 CVE-2026-25447 Improper Control of Generation of Code ('Code Injection') vulnerability in Jonathan Daggerhart Widget Wrangler widget-wrangler allows Code Injection.… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25429 Deserialization of Untrusted Data vulnerability in wpdive Nexa Blocks nexa-blocks allows Object Injection.This issue affects Nexa Blocks: from n/a th… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-25413 Unrestricted Upload of File with Dangerous Type vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Using Malicious Files.This issue affec… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-25377 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-cha… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-25371 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in King-Theme Lumise Product Designer lumise allow… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.9 CVE-2026-25366 Improper Control of Generation of Code ('Code Injection') vulnerability in Themeisle Woody ad snippets insert-php allows Code Injection.This issue af… Mitigation only Fix from $2,3002026-03-25