Export limit exceeded: 404439 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404439 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404439 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65459 | 2026-10-11 | 7.5 High | ||
| Unauthenticated Arbitrary Content Deletion in Forminator <= 1.57.3 versions. | ||||
| CVE-2026-62130 | 2026-10-11 | 7.2 High | ||
| Shop manager PHP Object Injection in WooCommerce Multilingual & Multicurrency <= 5.5.8 versions. | ||||
| CVE-2026-62129 | 2026-10-11 | 9.9 Critical | ||
| Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions. | ||||
| CVE-2026-62118 | 2026-10-11 | 7.3 High | ||
| Unauthenticated Broken Access Control in Barcode Scanner with Inventory & Order Manager <= 1.13.1 versions. | ||||
| CVE-2026-62098 | 2026-10-11 | 6.5 Medium | ||
| Unauthenticated Content Injection in Boutique <= 2.3.3 versions. | ||||
| CVE-2026-62046 | 2 Themerex Group, Wordpress-extensions | 2 Gutentype, Gutentype | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12. | ||||
| CVE-2026-62045 | 2 Themerex Group, Wordpress-extensions | 2 Booklovers, Booklovers | 2026-10-11 | 9.8 Critical |
| Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0. | ||||
| CVE-2026-62044 | 2026-10-11 | 7.2 High | ||
| Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13. | ||||
| CVE-2026-62038 | 2026-10-11 | 7.3 High | ||
| Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions. | ||||
| CVE-2026-62035 | 2026-10-11 | 6.3 Medium | ||
| Subscriber Broken Access Control in AWS S3 for WordPress Plugin – Upcasted <= 3.1.0 versions. | ||||
| CVE-2026-62033 | 2026-10-11 | 7.6 High | ||
| Subscriber Settings Change in uListing <= 2.2.0 versions. | ||||
| CVE-2026-62028 | 2026-10-11 | 5.4 Medium | ||
| Missing Authorization vulnerability in bPlugins Before After Image Comparison – Image comparison for WP before-after-image-compare allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Before After Image Comparison – Image comparison for WP: from n/a through 1.1.21. | ||||
| CVE-2026-62025 | 2026-10-11 | 9 Critical | ||
| Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions. | ||||
| CVE-2026-62024 | 2026-10-11 | 9.9 Critical | ||
| Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions. | ||||
| CVE-2026-62022 | 2026-10-11 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in Tonda Membership <= 1.0.1 versions. | ||||
| CVE-2026-62021 | 2026-10-11 | 8.8 High | ||
| Subscriber PHP Object Injection in Angio <= 1.1.1 versions. | ||||
| CVE-2026-5725 | 2026-10-11 | 6.1 Medium | ||
| The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | ||||
| CVE-2026-4791 | 2026-10-11 | 6.4 Medium | ||
| The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `logout-url` shortcode's 'button' attribute in all versions up to, and including, 8.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-42719 | 2026-10-11 | 9.8 Critical | ||
| Subscriber PHP Object Injection in Dynamic User Directory <= 2.4 versions. | ||||
| CVE-2026-42706 | 2026-10-11 | 7.5 High | ||
| Unauthenticated Broken Access Control in DK <= 3.2.1 versions. | ||||