Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

13,088 CVEs

CVEs (13,088, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 13,088 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-17021 MEDIUM Patched 5.3 2026-08-10 The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership o…
CVE-2026-17022 HIGH Patched 7.5 2026-08-10 The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps…
CVE-2026-17023 MEDIUM 4.8 2026-08-10 The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization call…
CVE-2026-17540 HIGH Patched 8.8 2026-08-10 The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and …
CVE-2026-17541 HIGH Patched 7.5 2026-08-10 The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity lo…
CVE-2026-17542 HIGH Patched 7.5 2026-08-10 The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such a…
CVE-2026-18030 HIGH Patched 8.1 2026-08-10 The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, a…
CVE-2026-18200 MEDIUM Patched 4.3 2026-08-10 The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, wi…
CVE-2026-18468 HIGH Patched 8.1 2026-08-10 The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the …
CVE-2026-18469 HIGH Patched 8.1 2026-08-10 The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification cod…
CVE-2026-18470 HIGH Patched 7.5 2026-08-10 The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the a…
CVE-2026-18666 MEDIUM Patched 4.3 2026-08-10 The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a…
CVE-2026-18786 HIGH Patched 8.8 2026-08-10 The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error ra…
CVE-2026-18934 MEDIUM Patched 5.5 2026-08-10 The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowin…
CVE-2026-18946 HIGH Patched 7.5 2026-08-10 The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible direct…
CVE-2026-18960 MEDIUM Patched 5.4 2026-08-10 The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application passw…
CVE-2026-19049 HIGH Patched 8.6 2026-08-10 The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without …
CVE-2026-19053 CRITICAL Patched 9.1 2026-08-10 The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, l…
CVE-2026-19074 MEDIUM Patched 5.3 2026-08-10 The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive informatio&hellip;
CVE-2026-19075 MEDIUM 5.0 2026-08-10 All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Publ&hellip;
CVE-2026-19077 MEDIUM Patched 6.5 2026-08-10 The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an ad&hellip;
CVE-2026-19089 CRITICAL Patched 9.8 2026-08-10 The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own do&hellip;
CVE-2026-21058 HIGH 7.1 2026-08-10 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
CVE-2026-21059 HIGH 7.1 2026-08-10 Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
CVE-2026-21060 MEDIUM 4.6 2026-08-10 Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.