Export limit exceeded: 399884 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (399884 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97239 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | ||||
| CVE-2026-97238 | 2026-09-30 | 5.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | ||||
| CVE-2026-97237 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | ||||
| CVE-2026-97236 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | ||||
| CVE-2026-97235 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. | ||||
| CVE-2026-97197 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. | ||||
| CVE-2026-97079 | 2026-09-30 | 4.3 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions. | ||||
| CVE-2026-97078 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions. | ||||
| CVE-2026-97077 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions. | ||||
| CVE-2026-97074 | 2026-09-30 | 4.3 Medium | ||
| Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | ||||
| CVE-2026-97067 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions. | ||||
| CVE-2026-97066 | 2026-09-30 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-97065 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions. | ||||
| CVE-2026-96886 | 2026-09-30 | 5.3 Medium | ||
| The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address and billing address of every customer who has booked a course. | ||||
| CVE-2026-96838 | 2026-09-30 | 8.8 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | ||||
| CVE-2026-96837 | 2026-09-30 | 8.8 High | ||
| Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions. | ||||
| CVE-2026-96836 | 2026-09-30 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. | ||||
| CVE-2026-96835 | 2026-09-30 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. | ||||
| CVE-2026-96834 | 2026-09-30 | 6.5 Medium | ||
| Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. | ||||
| CVE-2026-96833 | 2026-09-30 | 7.2 High | ||
| Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | ||||