Search
12,997 CVEs
CVEs (12,997, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 12,997 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-16032 | MEDIUM | Patched | 6.1 | 2026-08-09 | The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before storing it and rendering it … |
| CVE-2026-16957 | LOW | Patched | 2.7 | 2026-08-09 | The Slim SEO WordPress plugin before 4.9.11 does not restrict a post-meta preview feature to posts the user is allowed to edit, verifying only read access, allowing users … |
| CVE-2026-16965 | MEDIUM | Patched | 4.3 | 2026-08-09 | The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber … |
| CVE-2026-16988 | HIGH | Patched | 7.5 | 2026-08-09 | The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested listing, allowing unauthent… |
| CVE-2026-16992 | MEDIUM | Patched | 6.5 | 2026-08-09 | The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that route additionally publi… |
| CVE-2026-17011 | LOW | Patched | 3.8 | 2026-08-09 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor r… |
| CVE-2026-17014 | MEDIUM | Patched | 5.3 | 2026-08-09 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticat… |
| CVE-2026-17017 | HIGH | Patched | 8.1 | 2026-08-09 | The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an AJAX action, and does no… |
| CVE-2026-17044 | HIGH | Patched | 8.6 | 2026-08-09 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection expl… |
| CVE-2026-18032 | HIGH | Patched | 7.5 | 2026-08-09 | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that act… |
| CVE-2026-18037 | MEDIUM | Patched | 6.5 | 2026-08-09 | The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and that route additionall… |
| CVE-2026-18357 | HIGH | Patched | 7.5 | 2026-08-09 | The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated at… |
| CVE-2026-18464 | HIGH | Patched | 7.5 | 2026-08-09 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not… |
| CVE-2026-18465 | MEDIUM | Patched | 6.5 | 2026-08-09 | The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthenticated users, and does not… |
| CVE-2026-18473 | CRITICAL | Patched | 9.1 | 2026-08-09 | The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploita… |
| CVE-2026-18603 | MEDIUM | Patched | 6.5 | 2026-08-09 | The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previ… |
| CVE-2026-19335 | MEDIUM | 5.3 | 2026-08-09 | A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the file src/svc/utils/config… | |
| CVE-2026-19336 | MEDIUM | 5.3 | 2026-08-09 | A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/tools/approvals.ts. Perfo… | |
| CVE-2026-19337 | MEDIUM | 5.3 | 2026-08-09 | A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component read_webpage. Executing a … | |
| CVE-2026-19338 | MEDIUM | 5.3 | 2026-08-09 | A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index… | |
| CVE-2026-19339 | MEDIUM | 6.3 | 2026-08-09 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src… | |
| CVE-2026-19340 | MEDIUM | 6.3 | 2026-08-09 | A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js of the component Webhoo… | |
| CVE-2026-19341 | HIGH | 8.8 | 2026-08-09 | A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobalConfig. Such manipulati… | |
| CVE-2026-19342 | HIGH | 7.3 | 2026-08-09 | A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipu… | |
| CVE-2026-19343 | HIGH | 7.3 | 2026-08-09 | A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a… |