Export limit exceeded: 399868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 399868 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399868 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-94078 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions. | ||||
| CVE-2026-94077 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions. | ||||
| CVE-2026-94076 | 2026-09-30 | 8.8 High | ||
| Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions. | ||||
| CVE-2026-94074 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | ||||
| CVE-2026-93771 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions. | ||||
| CVE-2026-93770 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. | ||||
| CVE-2026-93651 | 2026-09-30 | 7.2 High | ||
| Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions. | ||||
| CVE-2026-93624 | 2026-09-30 | 7.2 High | ||
| Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | ||||
| CVE-2026-93621 | 2026-09-30 | 8.2 High | ||
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | ||||
| CVE-2026-93514 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions. | ||||
| CVE-2026-93512 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | ||||
| CVE-2026-62085 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | ||||
| CVE-2026-62083 | 2026-09-30 | 5.4 Medium | ||
| Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions. | ||||
| CVE-2026-62081 | 2026-09-30 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions. | ||||
| CVE-2026-62080 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions. | ||||
| CVE-2026-62079 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions. | ||||
| CVE-2026-62078 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions. | ||||
| CVE-2026-27371 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions. | ||||
| CVE-2026-27085 | 2026-09-30 | 2.7 Low | ||
| Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. | ||||
| CVE-2026-91206 | 1 Apache | 1 Roller | 2026-09-30 | 6.1 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Apache Roller 6.1.5 allows a remote attacker to perform reflected cross-site scripting through the optional LDAP comment authenticator, which writes request parameter values into its HTML form without escaping. This affects only sites configured to use LdapCommentAuthenticator, and a victim whose session has already loaded the authenticator form must follow a crafted link. Users are recommended to upgrade to Apache Roller 6.1.6 or later, which escapes the reflected values. | ||||