Export limit exceeded: 369876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 369876 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369876 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-65480 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions. | ||||
| CVE-2026-65479 | 2026-07-23 | 5.4 Medium | ||
| Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. | ||||
| CVE-2026-27064 | 2026-07-23 | 9.1 Critical | ||
| Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | ||||
| CVE-2026-27377 | 2026-07-23 | 6.7 Medium | ||
| Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | ||||
| CVE-2026-15448 | 2 Tickera, Wordpress | 2 Tickera – Sell Tickets & Manage Events, Wordpress | 2026-07-23 | 6.5 Medium |
| The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-65538 | 2026-07-23 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | ||||
| CVE-2026-65537 | 2026-07-23 | 4.3 Medium | ||
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | ||||
| CVE-2026-65518 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | ||||
| CVE-2026-65506 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | ||||
| CVE-2026-65498 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-65491 | 2026-07-23 | 4.3 Medium | ||
| Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions. | ||||
| CVE-2026-65486 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. | ||||
| CVE-2026-65485 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | ||||
| CVE-2026-65473 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions. | ||||
| CVE-2026-65461 | 2026-07-23 | 9.1 Critical | ||
| Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. | ||||
| CVE-2026-65454 | 2026-07-23 | 8.5 High | ||
| Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions. | ||||
| CVE-2026-61947 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | ||||
| CVE-2026-59555 | 2026-07-23 | 10 Critical | ||
| Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | ||||
| CVE-2026-59542 | 2026-07-23 | 7.7 High | ||
| Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions. | ||||
| CVE-2026-59540 | 2026-07-23 | 9.8 Critical | ||
| Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. | ||||