Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-16079 The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and i… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.5 CVE-2026-15963 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz … No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-15726 The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and inclu… No fix yet Fix from $4,0002026-08-16 MEDIUM 5.3 CVE-2026-15441 The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' … No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-15066 The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and includ… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.1 CVE-2026-15009 The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site… No fix yet Fix from $4,0002026-08-16 HIGH 7.2 CVE-2026-15002 The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 v… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.1 CVE-2026-14524 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDe… No fix yet Fix from $5,7502026-08-16 HIGH 8.8 CVE-2026-14498 The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' paramet… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.5 CVE-2026-13358 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.4 CVE-2026-11780 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_tit… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19930 A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User … Patch available Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19929 A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/ware… Patch available Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19928 A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/R… Patch available Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19927 A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/… Patch available Fix from $4,0002026-08-16 HIGH 7.3 CVE-2026-19926 A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-ga… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.8 CVE-2026-19924 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th… No fix yet Fix from $5,7502026-08-16 MEDIUM 6.3 CVE-2026-19923 A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19921 A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /h… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19920 A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulatio… No fix yet Fix from $4,0002026-08-16 HIGH 7.3 CVE-2026-19919 A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.3 CVE-2026-19918 A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19917 A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. … No fix yet Fix from $4,0002026-08-15 HIGH 8.7 CVE-2026-74767 Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from … Patch available Fix from $4,9002026-08-15 CRITICAL 10.0 CVE-2026-74764 Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor p… Patch available Fix from $5,7502026-08-15 HIGH 7.5 CVE-2026-73054 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parame… No fix yet Fix from $4,9002026-08-15 CRITICAL 9.0 CVE-2026-73053 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73052 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73050 SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu… No fix yet Fix from $5,7502026-08-15 MEDIUM 6.2 CVE-2026-73047 siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature … No fix yet Fix from $4,0002026-08-15