Export limit exceeded: 373344 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (373344 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65545 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | ||||
| CVE-2026-65544 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions. | ||||
| CVE-2026-65543 | 2026-08-06 | 7.5 High | ||
| Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions. | ||||
| CVE-2026-65541 | 2026-08-06 | 7.3 High | ||
| Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions. | ||||
| CVE-2026-65520 | 2026-08-06 | 9.3 Critical | ||
| Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions. | ||||
| CVE-2026-65517 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions. | ||||
| CVE-2026-65515 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | ||||
| CVE-2026-65513 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | ||||
| CVE-2026-61959 | 2026-08-06 | 6.5 Medium | ||
| Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions. | ||||
| CVE-2026-32469 | 2026-08-06 | 5.3 Medium | ||
| Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions. | ||||
| CVE-2026-28183 | 2026-08-06 | 7.2 High | ||
| Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions. | ||||
| CVE-2026-28177 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. | ||||
| CVE-2026-28172 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | ||||
| CVE-2026-28141 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions. | ||||
| CVE-2026-28140 | 2026-08-06 | 7.5 High | ||
| Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | ||||
| CVE-2026-28139 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | ||||
| CVE-2026-28005 | 2026-08-06 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | ||||
| CVE-2026-25403 | 2026-08-06 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-19028 | 2026-08-06 | N/A | ||
| H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools. | ||||
| CVE-2026-14829 | 2026-08-06 | 8.2 High | ||
| The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its license-management functionality, relying on a shared secret computed entirely from publicly available information, allowing unauthenticated attackers to deactivate the Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13's premium licensing state and erase the stored license key. | ||||