Export limit exceeded: 402794 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402794 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 402794 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402794 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-97309 | 2026-10-06 | N/A | ||
| Missing Authorization vulnerability in Webful Creations RepairBuddy computer-repair-shop allows Retrieve Embedded Sensitive Data.This issue affects RepairBuddy: from n/a through 4.1226. | ||||
| CVE-2026-97303 | 2026-10-06 | 7.6 High | ||
| Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2. | ||||
| CVE-2026-97300 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in WP Event Solution <= 4.1.25 versions. | ||||
| CVE-2026-97275 | 2026-10-06 | 5.3 Medium | ||
| Improper Validation of Specified Quantity in Input vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder woo-product-builder allows Input Data Manipulation.This issue affects BuildKit – Product Builder for WooCommerce – Custom PC Builder: from n/a through 1.0.28. | ||||
| CVE-2026-97257 | 2026-10-06 | 8.8 High | ||
| Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7. | ||||
| CVE-2026-97071 | 2026-10-06 | 5.3 Medium | ||
| Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17. | ||||
| CVE-2026-94299 | 2026-10-06 | 6.5 Medium | ||
| The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated attackers to forge payment confirmations and change the status of arbitrary orders on any installation where that secret has been left at its default empty value. | ||||
| CVE-2026-94278 | 2026-10-06 | 5.5 Medium | ||
| The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that referenced the old file path. | ||||
| CVE-2026-93617 | 2026-10-06 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1. | ||||
| CVE-2026-41563 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions. | ||||
| CVE-2026-41558 | 2026-10-06 | 7.5 High | ||
| Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions. | ||||
| CVE-2026-39791 | 2026-10-06 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions. | ||||
| CVE-2026-39789 | 2026-10-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions. | ||||
| CVE-2026-39760 | 2026-10-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions. | ||||
| CVE-2026-39757 | 2026-10-06 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions. | ||||
| CVE-2026-39756 | 2026-10-06 | 6.5 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions. | ||||
| CVE-2026-39755 | 2026-10-06 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. | ||||
| CVE-2026-39754 | 2026-10-06 | 6.5 Medium | ||
| Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions. | ||||
| CVE-2026-39753 | 2026-10-06 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions. | ||||
| CVE-2026-39752 | 2026-10-06 | 7.7 High | ||
| Contributor Arbitrary File Deletion in Jobs for WordPress <= 2.8.2 versions. | ||||