Export limit exceeded: 394175 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 394175 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (394175 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-73999 | 2026-09-17 | 5.4 Medium | ||
| Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. | ||||
| CVE-2026-66676 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. | ||||
| CVE-2026-66631 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. | ||||
| CVE-2026-66630 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | ||||
| CVE-2026-66628 | 2026-09-17 | 7.6 High | ||
| Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. | ||||
| CVE-2026-66626 | 2026-09-17 | 7.6 High | ||
| Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. | ||||
| CVE-2026-66625 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. | ||||
| CVE-2026-66624 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. | ||||
| CVE-2026-66619 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in Newsletters <= 4.18 versions. | ||||
| CVE-2026-66618 | 2026-09-17 | 7.6 High | ||
| Administrator SQL Injection in WP Maps <= 4.9.9 versions. | ||||
| CVE-2026-66617 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | ||||
| CVE-2026-66608 | 2026-09-17 | 6.4 Medium | ||
| Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | ||||
| CVE-2026-66580 | 2026-09-17 | 8.5 High | ||
| Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | ||||
| CVE-2026-66578 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | ||||
| CVE-2026-66575 | 2026-09-17 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. | ||||
| CVE-2026-66574 | 2026-09-17 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. | ||||
| CVE-2026-66571 | 2026-09-17 | 7.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. | ||||
| CVE-2026-62108 | 2026-09-17 | 9.8 Critical | ||
| Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. | ||||
| CVE-2026-62104 | 2026-09-17 | 10 Critical | ||
| Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. | ||||
| CVE-2026-62101 | 2026-09-17 | 9.8 Critical | ||
| Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. | ||||