Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-18570 A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-16292 The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing… No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-16540 The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own rec… No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-16285 The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a… No fix yet Fix from $1,9502026-08-02 CRITICAL 9.8 CVE-2026-16256 The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us… No fix yet Fix from $2,3002026-08-02 HIGH 7.5 CVE-2026-16261 The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it iss… No fix yet Fix from $1,9502026-08-02 MEDIUM 6.6 CVE-2026-16062 The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its… No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-16064 The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when qui… No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-16063 The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with p… No fix yet Fix from $1,6002026-08-02 MEDIUM 5.5 CVE-2026-15248 The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing … No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-15385 The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-men… No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-15241 The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing … No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-15236 The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the con… No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-15206 The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after a… No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-15151 The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users … No fix yet Fix from $1,9502026-08-02 HIGH 8.2 CVE-2026-14920 ## Summary No fix yet Fix from $1,9502026-08-02 MEDIUM 5.4 CVE-2026-14864 The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users wit… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.1 CVE-2026-14841 The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribu… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.8 CVE-2026-14817 The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a… No fix yet Fix from $1,6002026-08-02 HIGH 8.1 CVE-2026-12586 The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CS… No fix yet Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-13389 The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthen… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-9335 A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalL… Patch available Fix from $1,6002026-08-02 CRITICAL 9.8 CVE-2026-8457 The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to … No fix yet Fix from $2,3002026-08-02 HIGH 7.5 CVE-2026-18352 The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' p… No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-13339 The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_c… No fix yet Fix from $1,9502026-08-02 HIGH 7.4 CVE-2026-18556 KEV Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-centra… N Central after 2026.1 Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-55735 Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged … Guardian 2.4.1+ Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-55734 Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via… Guardian 2.4.1+ Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-55733 Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-control… Guardian 2.4.1+ Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-54894 Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influen… Guardian 2.4.1+ Fix from $1,9502026-08-01