Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-64871 NONE — 2026-07-23 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a …
CVE-2026-64799 NONE — 2026-07-23 Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request privat…
CVE-2026-16078 MEDIUM 6.5 2026-07-23 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' …
CVE-2026-15906 MEDIUM 6.5 2026-07-23 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and inc…
CVE-2026-15827 MEDIUM 5.3 2026-07-23 The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and …
CVE-2026-15794 MEDIUM 6.4 2026-07-23 The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including…
CVE-2026-15786 MEDIUM 4.9 2026-07-23 The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up …
CVE-2026-15761 MEDIUM 6.5 2026-07-23 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and includ…
CVE-2026-15647 MEDIUM 4.4 2026-07-23 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.…
CVE-2026-15646 MEDIUM 6.4 2026-07-23 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due…
CVE-2026-15448 MEDIUM 6.5 2026-07-23 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and…
CVE-2026-15404 MEDIUM 6.4 2026-07-23 The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input san…
CVE-2026-15394 MEDIUM 6.4 2026-07-23 The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all v…
CVE-2026-15348 MEDIUM 6.3 2026-07-23 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmp…
CVE-2026-15017 HIGH 8.8 2026-07-23 The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks…
CVE-2026-15015 CRITICAL 9.8 2026-07-23 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugi…
CVE-2026-15011 CRITICAL 9.8 2026-07-23 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due …
CVE-2026-14481 MEDIUM 6.4 2026-07-23 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' para…
CVE-2026-14282 CRITICAL 9.8 2026-07-23 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in…
CVE-2026-13119 MEDIUM 6.5 2026-07-23 The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJA…
CVE-2026-13009 MEDIUM 6.5 2026-07-23 The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due…
CVE-2026-52688 HIGH 7.5 2026-07-23 RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-52686 LOW 3.7 2026-07-23 The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME o…
CVE-2026-52684 LOW 3.7 2026-07-23 If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then th…
CVE-2026-16723 CRITICAL 9.0 2026-07-23 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no Au…