Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

1,463 CVEs

EOL hidden · Show all products

CVEs (1,463, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 1,463 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9851 HIGH 7.2 2026-06-06 The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capab…
CVE-2026-9844 NONE Patched — 2026-06-02 Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This …
CVE-2026-9829 MEDIUM 6.5 2026-06-06 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'compact_album_order_by' Shortcode Parameter i…
CVE-2026-9732 MEDIUM 4.3 2026-06-03 The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This …
CVE-2026-9730 MEDIUM 4.3 2026-06-02 The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or inco…
CVE-2026-9723 MEDIUM 4.3 2026-06-02 The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect…
CVE-2026-9722 MEDIUM 4.3 2026-06-02 The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce valid…
CVE-2026-9719 MEDIUM 4.3 2026-06-06 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5…
CVE-2026-9669 NONE — 2026-06-08 bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted inpu…
CVE-2026-9599 MEDIUM 4.3 2026-06-02 The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce vali…
CVE-2026-9594 MEDIUM 4.4 2026-06-06 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location…
CVE-2026-9590 MEDIUM Patched 5.3 2026-06-02 Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify…
CVE-2026-9549 MEDIUM 4.8 2026-06-08 Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can c&hellip;
CVE-2026-9522 MEDIUM Patched 5.4 2026-06-02 Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to d&hellip;
CVE-2026-9516 HIGH Patched 7.5 2026-06-03 Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BO&hellip;
CVE-2026-9506 NONE &mdash; 2026-06-08 This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could explo&hellip;
CVE-2026-9334 HIGH Patched 7.3 2026-06-03 Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object k&hellip;
CVE-2026-9290 HIGH 7.5 2026-06-06 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (pro&hellip;
CVE-2026-9281 MEDIUM 6.4 2026-06-06 The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'j&hellip;
CVE-2026-9280 MEDIUM 6.1 2026-06-06 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and&hellip;
CVE-2026-9270 CRITICAL 9.1 2026-06-05 DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from unt&hellip;
CVE-2026-9234 MEDIUM 4.3 2026-06-02 The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability che&hellip;
CVE-2026-9197 MEDIUM 4.9 2026-06-06 The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it&hellip;
CVE-2026-9088 LOW 2.7 2026-06-05 A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the g&hellip;
CVE-2026-9050 MEDIUM 4.3 2026-06-02 The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not prope&hellip;