Export limit exceeded: 404425 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (404425 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-45440 2026-10-11 7.6 High
Administrator SQL Injection in WP Ultimate CSV Importer <= 9.2 versions.
CVE-2026-42777 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.
CVE-2026-42724 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in CleanSkin <= 1.5.0 versions.
CVE-2026-42723 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in CleanSkin <= 1.5.0 versions.
CVE-2026-42722 2026-10-11 7.6 High
Administrator SQL Injection in Frontend Admin by DynamiApps <= 3.29.13 versions.
CVE-2026-42718 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Booster for WooCommerce <= 8.4.0 versions.
CVE-2026-42717 2026-10-11 7.6 High
Administrator SQL Injection in Leyka <= 3.32.3 versions.
CVE-2026-42716 2026-10-11 9.8 Critical
Unauthenticated PHP Object Injection in Payever - WooCommerce Gateway <= 4.8.2 versions.
CVE-2026-42715 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Photo Gallery by 10Web <= 1.8.47 versions.
CVE-2026-42712 2026-10-11 8.5 High
Subscriber SQL Injection in Qode Tours <= 3.1.3.2 versions.
CVE-2026-42711 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Slider by 10Web <= 1.2.63 versions.
CVE-2026-42709 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Food Menu – Restaurant Menu & Online Ordering for WooCommerce <= 6.0.5 versions.
CVE-2026-42704 2026-10-11 8.1 High
Unauthenticated Local File Inclusion in Kids Care <= 3.2.4 versions.
CVE-2026-42702 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Tutor LMS <= 4.1.0 versions.
CVE-2026-42699 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions.
CVE-2026-42697 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions.
CVE-2026-42695 2026-10-11 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Flowplayer Video Player fv-wordpress-flowplayer allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.54.7212.
CVE-2026-42693 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Jannah <= 7.6.5 versions.
CVE-2026-42633 2026-10-11 8.5 High
Subscriber SQL Injection in Events Manager <= 7.4.6 versions.
CVE-2026-42632 2026-10-11 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Qode Real Estate <= 1.1.7.3 versions.