Export limit exceeded: 399868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 399868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (399868 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-94078 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.
CVE-2026-94077 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.
CVE-2026-94076 2026-09-30 8.8 High
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
CVE-2026-94074 2026-09-30 6.5 Medium
Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.
CVE-2026-93771 2026-09-30 7.2 High
Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.
CVE-2026-93770 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-93651 2026-09-30 7.2 High
Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.
CVE-2026-93624 2026-09-30 7.2 High
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
CVE-2026-93621 2026-09-30 8.2 High
Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.
CVE-2026-93514 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.
CVE-2026-93512 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
CVE-2026-62085 2026-09-30 7.6 High
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
CVE-2026-62083 2026-09-30 5.4 Medium
Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.
CVE-2026-62081 2026-09-30 5.4 Medium
Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.
CVE-2026-62080 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.
CVE-2026-62079 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.
CVE-2026-62078 2026-09-30 6.5 Medium
Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.
CVE-2026-27371 2026-09-30 7.1 High
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
CVE-2026-27085 2026-09-30 2.7 Low
Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions.
CVE-2026-91206 1 Apache 1 Roller 2026-09-30 6.1 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values.