Search
11,582 CVEs · High severity
CVEs (11,582, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 11,582 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-86169 | HIGH | 8.8 | 2026-09-05 | Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the sec… | |
| CVE-2026-86123 | HIGH | 8.7 | 2026-09-05 | SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified… | |
| CVE-2026-86119 | HIGH | 8.6 | 2026-09-05 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGI… | |
| CVE-2026-86117 | HIGH | 8.1 | 2026-09-05 | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address w… | |
| CVE-2026-83625 | HIGH | 7.2 | 2026-09-05 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to in… | |
| CVE-2026-81543 | HIGH | 8.8 | 2026-09-05 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capab… | |
| CVE-2026-84935 | HIGH | Patched | 8.0 | 2026-09-05 | The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those st… |
| CVE-2026-84934 | HIGH | Patched | 8.0 | 2026-09-05 | The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal actio… |
| CVE-2026-82304 | HIGH | Patched | 8.6 | 2026-09-05 | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthe… |
| CVE-2026-81404 | HIGH | Patched | 7.1 | 2026-09-05 | The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated attacke… |
| CVE-2026-78438 | HIGH | 7.2 | 2026-09-05 | The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, and includin… | |
| CVE-2026-77830 | HIGH | 7.2 | 2026-09-05 | The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all ve… | |
| CVE-2026-77826 | HIGH | Patched | 8.8 | 2026-09-05 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, all… |
| CVE-2026-19887 | HIGH | 8.8 | 2026-09-05 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the… | |
| CVE-2026-19858 | HIGH | Patched | 7.5 | 2026-09-05 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rende… |
| CVE-2026-19769 | HIGH | 7.2 | 2026-09-05 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unm… | |
| CVE-2026-18406 | HIGH | 7.2 | 2026-09-05 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded … | |
| CVE-2026-16649 | HIGH | 7.2 | 2026-09-05 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficie… | |
| CVE-2026-15984 | HIGH | 7.2 | 2026-09-05 | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient … | |
| CVE-2026-86145 | HIGH | Patched | 8.2 | 2026-09-05 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even t… |
| CVE-2026-77263 | HIGH | 7.2 | 2026-09-05 | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versi… | |
| CVE-2026-77233 | HIGH | 7.2 | 2026-09-05 | The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense … | |
| CVE-2026-86140 | HIGH | Patched | 8.0 | 2026-09-05 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. |
| CVE-2026-52775 | HIGH | Patched | 8.8 | 2026-09-05 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::de… |
| CVE-2026-52771 | HIGH | Patched | 8.3 | 2026-09-05 | YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a … |