Search
Search Results (370925 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-57374 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | ||||
| CVE-2026-57696 | 2 Videowhisper, Wordpress | 2 Picture Gallery, Wordpress | 2026-07-23 | 7.1 High |
| Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | ||||
| CVE-2026-57717 | 2026-07-23 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. | ||||
| CVE-2026-57808 | 2 Saad Iqbal, Wordpress | 2 Wp Easypay, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. | ||||
| CVE-2026-57716 | 2 Videowhisper, Wordpress | 2 Broadcast Live Video, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | ||||
| CVE-2026-65474 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Ninja Tables | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | ||||
| CVE-2026-64802 | 1 Jetbrains | 1 Goland | 2026-07-23 | 7.8 High |
| In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration | ||||
| CVE-2026-64806 | 1 Jetbrains | 1 Webstorm | 2026-07-23 | 8.4 High |
| In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter | ||||
| CVE-2026-65908 | 1 Jetbrains | 1 Pycharm | 2026-07-23 | 8.6 High |
| In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open | ||||
| CVE-2026-59522 | 2 Wedevs, Wordpress | 2 Wp Erp, Wordpress | 2026-07-23 | 6.5 Medium |
| Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | ||||
| CVE-2026-61949 | 2 Bookly, Wordpress | 2 Bookly, Wordpress | 2026-07-23 | 9.3 Critical |
| Unauthenticated SQL Injection in Bookly <= 27.7 versions. | ||||
| CVE-2026-61981 | 2026-07-23 | 5.4 Medium | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions. | ||||
| CVE-2026-65454 | 2026-07-23 | 8.5 High | ||
| Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | ||||
| CVE-2026-65467 | 2026-07-23 | 4.9 Medium | ||
| Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | ||||
| CVE-2026-65498 | 2 Complianz, Wordpress | 2 Complianz, Wordpress | 2026-07-23 | 5.3 Medium |
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-65518 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | ||||
| CVE-2026-65526 | 2 Themeisle, Wordpress | 2 Visualizer, Wordpress | 2026-07-23 | 8.5 High |
| Contributor SQL Injection in Visualizer <= 4.0.6 versions. | ||||
| CVE-2026-65532 | 2 Persianscript, Wordpress | 2 Persian Woocommerce Sms, Wordpress | 2026-07-23 | 7.6 High |
| Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions. | ||||
| CVE-2026-65475 | 2 Wordpress, Wpchill | 2 Wordpress, Modula Image Gallery | 2026-07-23 | 6.5 Medium |
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Modula Image Gallery allows Stored XSS. This issue affects Modula Image Gallery: from 2.14.25 through 2.14.30. | ||||
| CVE-2026-65898 | 1 Cure53 | 1 Dompurify | 2026-07-23 | 7.2 High |
| DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as stored XSS. | ||||