Export limit exceeded: 381902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (94602 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-61982 2 Jp-secure, Wordpress 2 Siteguard Wp Plugin, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-65509 2 Wordpress, Wpdatatables 2 Wordpress, Wpdatatables 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-66439 2 Berocket, Wordpress 2 Advanced Ajax Product Filters, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
CVE-2026-65545 2 Jordy Meow, Wordpress 2 Ai-engine, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions.
CVE-2026-65560 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
CVE-2026-66457 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
CVE-2026-3430 2026-08-06 8.6 High
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
CVE-2026-66702 2 Rank Math Seo, Wordpress 2 Rank Math Seo, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
CVE-2026-65559 2 Tychesoftwares, Wordpress 2 Order Delivery Date For Woocommerce, Wordpress 2026-08-06 7.2 High
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
CVE-2026-65513 2 Nsquared, Wordpress 2 Simply Schedule Appointments, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65515 2 Affiliatewp, Wordpress 2 Affiliatewp, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
CVE-2026-65547 2 Constantcontact, Wordpress 2 Creative Mail, Wordpress 2026-08-06 8.5 High
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
CVE-2026-65549 2026-08-06 7.2 High
Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVE-2026-65565 2 Ays-pro, Wordpress 2 Survey Maker, Wordpress 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions.
CVE-2026-65569 2 Wordpress, Wpjobportal 2 Wordpress, Wp Job Portal 2026-08-06 8.5 High
Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions.
CVE-2026-61964 2 Wordpress, Wpmanageninja 2 Wordpress, Ninja Tables 2026-08-06 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
CVE-2026-67551 1 Apache 2 Qpid Proton-dotnet, Qpid Proton Dotnet 2026-08-06 7.5 High
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
CVE-2026-18510 2 Cozmoslabs, Wordpress 2 Translatepress – Translate Multilingual Sites With Ai Translation, Wordpress 2026-08-06 7.2 High
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-time commenters, but does not prevent it, as the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unmodified.
CVE-2025-11362 2 Pdfmake, Pdfmake Project 2 Pdfmake, Pdfmake 2026-08-06 7.5 High
Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition.
CVE-2024-21549 1 Spatie 1 Browsershot 2026-08-06 8.6 High
Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).