Search
3,449 CVEs · Medium severity
CVEs (3,449, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,449 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-11614 | MEDIUM | 6.4 | 2026-06-24 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, … | |
| CVE-2026-12488 | MEDIUM | 6.2 | 2026-06-24 | A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted network request can lead to a denial of servic… | |
| CVE-2026-9539 | MEDIUM | 6.5 | 2026-06-24 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environmen… | |
| CVE-2026-10531 | MEDIUM | Patched | 5.4 | 2026-06-24 | The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with t… |
| CVE-2026-10552 | MEDIUM | 4.3 | 2026-06-24 | The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or incorrect nonce validatio… | |
| CVE-2026-11370 | MEDIUM | 6.4 | 2026-06-24 | The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it p… | |
| CVE-2026-11997 | MEDIUM | 4.3 | 2026-06-24 | The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing or incorrect nonce validatio… | |
| CVE-2026-12094 | MEDIUM | 5.3 | 2026-06-24 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_use… | |
| CVE-2026-6292 | MEDIUM | 4.3 | 2026-06-24 | The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is due to a completely bro… | |
| CVE-2026-7617 | MEDIUM | 5.3 | 2026-06-24 | The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying th… | |
| CVE-2026-8614 | MEDIUM | 4.3 | 2026-06-24 | The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin… | |
| CVE-2026-8617 | MEDIUM | 5.3 | 2026-06-24 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capabi… | |
| CVE-2026-8622 | MEDIUM | 6.1 | 2026-06-24 | The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to… | |
| CVE-2026-8628 | MEDIUM | 6.1 | 2026-06-24 | The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficien… | |
| CVE-2026-8688 | MEDIUM | 4.3 | 2026-06-24 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve… | |
| CVE-2026-8690 | MEDIUM | 5.3 | 2026-06-24 | The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the p… | |
| CVE-2026-8865 | MEDIUM | 6.4 | 2026-06-24 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and in… | |
| CVE-2026-8896 | MEDIUM | 6.4 | 2026-06-24 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_tex… | |
| CVE-2026-8905 | MEDIUM | 6.1 | 2026-06-24 | The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect … | |
| CVE-2026-9172 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability … | |
| CVE-2026-9175 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This… | |
| CVE-2026-9183 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block… | |
| CVE-2026-9184 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX fu… | |
| CVE-2026-9612 | MEDIUM | 5.3 | 2026-06-24 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the y… | |
| CVE-2026-9616 | MEDIUM | 4.3 | 2026-06-24 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly ve… |