Search
Search Results (404437 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-62067 | 2026-10-11 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Kaven <= 1.2 versions. | ||||
| CVE-2026-62066 | 2026-10-11 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Volos <= 1.2 versions. | ||||
| CVE-2026-62065 | 2026-10-11 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Cardea <= 2.3 versions. | ||||
| CVE-2026-62064 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ambed <= 1.0.0 versions. | ||||
| CVE-2026-62054 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Yacht Rental <= 2.6 versions. | ||||
| CVE-2026-62053 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Wine House <= 3.20 versions. | ||||
| CVE-2026-62052 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Tipsy <= 1.6 versions. | ||||
| CVE-2026-62051 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Stargaze <= 1.10 versions. | ||||
| CVE-2026-62050 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated PHP Object Injection in Splendour <= 1.23 versions. | ||||
| CVE-2026-62043 | 2026-10-11 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Contact Form 7 – Dynamic Text Extension <= 5.0.7 versions. | ||||
| CVE-2026-62039 | 2026-10-11 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.8.8. | ||||
| CVE-2026-62037 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Document Embedder <= 2.4.0 versions. | ||||
| CVE-2026-62034 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Before After Image Comparison – Image comparison for WP <= 1.1.21 versions. | ||||
| CVE-2026-62032 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated Local File Inclusion in DirectoryPress <= 3.6.27 versions. | ||||
| CVE-2026-62031 | 2026-10-11 | 9.3 Critical | ||
| Unauthenticated SQL Injection in uListing <= 2.2.0 versions. | ||||
| CVE-2026-62030 | 2026-10-11 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in StreamCast <= 2.4.5 versions. | ||||
| CVE-2026-62027 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Team Section Block <= 2.0.4 versions. | ||||
| CVE-2026-62020 | 2026-10-11 | 8.1 High | ||
| Unauthenticated Local File Inclusion in TouchUp < 1.4 versions. | ||||
| CVE-2026-57806 | 2026-10-11 | 7.1 High | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in drfuri Martfury - WooCommerce Marketplace WordPress Theme martfury allows Reflected XSS.This issue affects Martfury - WooCommerce Marketplace WordPress Theme: from n/a through 3.3.9. | ||||
| CVE-2026-57742 | 1 Themerex Group | 1 Kids Planet | 2026-10-11 | 7.1 High |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group Kids Planet allows Reflected XSS. This issue affects Kids Planet: from n/a through 2.2.14.2. | ||||