Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-18367 A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 a… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-17032 Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attacker… No fix yet Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-16620 The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Se… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-16619 The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a … No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-15734 A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary c… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-15733EPSS 14% A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attack… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-15732 A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated att… No fix yet Fix from $2,3002026-08-06 MEDIUM 5.3 CVE-2026-16067 The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-15208 The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against th… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-15152 The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own mercha… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-15149 The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-15147 The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to v… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14936 The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14842 The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauth… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14831 The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when a… No fix yet Fix from $1,6002026-08-06 CRITICAL 10.0 CVE-2026-14812 The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, … No fix yet Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-13399 The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unau… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-13342 The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, … No fix yet Fix from $1,6002026-08-06 MEDIUM 5.9 CVE-2026-12901 The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated atta… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-12584 The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notific… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-12501 The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured mer… No fix yet Fix from $1,6002026-08-06 CRITICAL 10.0 CVE-2026-11976 The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) … No fix yet Fix from $2,3002026-08-06 HIGH 7.8 CVE-2026-11803 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage thi… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.9 CVE-2026-11361 The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-10599 The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order bein… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-10524 The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the c… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.0 CVE-2025-14561 In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing suffici… No fix yet Fix from $2,3002026-08-06 MEDIUM 5.0 CVE-2025-12317 When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens assoc… No fix yet Fix from $1,6002026-08-06 HIGH 8.8 CVE-2024-39024 In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution. No fix yet Fix from $1,9502026-08-06 MEDIUM 6.8 CVE-2024-6541 The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows aut… No fix yet Fix from $1,6002026-08-06