Export limit exceeded: 384505 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (384505 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-66594 | 2 Lukeseager, Wordpress | 2 Wordpress Persistent Login, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions. | ||||
| CVE-2026-66598 | 2 Kingtech Llc., Wordpress | 2 B2bking Premium, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions. | ||||
| CVE-2026-66605 | 2 Hasthemes, Wordpress | 2 Swatchly – Woocommerce Variation Swatches For Products, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | ||||
| CVE-2026-66606 | 2 Themegrill, Wordpress | 2 Smartsmtp, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions. | ||||
| CVE-2026-66609 | 2 Codexthemes, Wordpress | 2 Thegem (elementor), Wordpress | 2026-08-21 | 9.3 Critical |
| Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | ||||
| CVE-2026-66647 | 2 Radiustheme, Wordpress | 2 Homlisti, Wordpress | 2026-08-21 | 6.5 Medium |
| Subscriber Broken Access Control in Homlisti <= 3.1.2 versions. | ||||
| CVE-2026-66672 | 2 Monkeysan, Wordpress | 2 Flatastic, Wordpress | 2026-08-21 | 9.8 Critical |
| Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions. | ||||
| CVE-2026-66673 | 2 Monkeysan, Wordpress | 2 Flatastic, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions. | ||||
| CVE-2026-66677 | 2 Vaultdweller, Wordpress | 2 Leyka, Wordpress | 2026-08-21 | 7.6 High |
| Subscriber Broken Authentication in Leyka <= 3.32.3 versions. | ||||
| CVE-2026-68564 | 2 Notificationx, Wordpress | 2 Notificationx Pro, Wordpress | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions. | ||||
| CVE-2026-73998 | 2 Axew3, Wordpress | 2 Wp W3all Phpbb, Wordpress | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions. | ||||
| CVE-2026-74013 | 2 Wordpress, Wordpress.com | 2 Wordpress, Eshipper Commerce | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions. | ||||
| CVE-2026-74014 | 2 Indithemes, Wordpress | 2 It Residence, Wordpress | 2026-08-21 | 9.9 Critical |
| Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions. | ||||
| CVE-2026-74016 | 2 Themagnifico52, Wordpress | 2 Smart Cleaning, Wordpress | 2026-08-21 | 9.9 Critical |
| Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | ||||
| CVE-2026-74018 | 2 Themagnifico52, Wordpress | 2 Warehouse Cargo, Wordpress | 2026-08-21 | 9.9 Critical |
| Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions. | ||||
| CVE-2026-74020 | 2 Anders Norén, Wordpress | 2 Koji, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Koji <= 2.2.1 versions. | ||||
| CVE-2025-62307 | 1 Hcl Software | 1 Iem | 2026-08-21 | 5.4 Medium |
| HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | ||||
| CVE-2025-62306 | 1 Hcl Software | 1 Iem | 2026-08-21 | 5 Medium |
| HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were to gain access to the application, the insufficient logging could hinder incident response. | ||||
| CVE-2026-28163 | 2 Mycred, Wordpress | 2 New User Approve, Wordpress | 2026-08-21 | 5.3 Medium |
| Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8. | ||||
| CVE-2026-15706 | 1 Baylan Measuring Instruments Industry And Trade Inc. | 1 Baylan Smart Meter Management Application (bms) | 2026-08-21 | 9.8 Critical |
| Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142. | ||||