Export limit exceeded: 381902 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (94602 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-61982 | 2 Jp-secure, Wordpress | 2 Siteguard Wp Plugin, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions. | ||||
| CVE-2026-65509 | 2 Wordpress, Wpdatatables | 2 Wordpress, Wpdatatables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | ||||
| CVE-2026-66439 | 2 Berocket, Wordpress | 2 Advanced Ajax Product Filters, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions. | ||||
| CVE-2026-65545 | 2 Jordy Meow, Wordpress | 2 Ai-engine, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AI Engine <= 3.6.8 versions. | ||||
| CVE-2026-65560 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | ||||
| CVE-2026-66457 | 2026-08-06 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions. | ||||
| CVE-2026-3430 | 2026-08-06 | 8.6 High | ||
| The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | ||||
| CVE-2026-66702 | 2 Rank Math Seo, Wordpress | 2 Rank Math Seo, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions. | ||||
| CVE-2026-65559 | 2 Tychesoftwares, Wordpress | 2 Order Delivery Date For Woocommerce, Wordpress | 2026-08-06 | 7.2 High |
| Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. | ||||
| CVE-2026-65513 | 2 Nsquared, Wordpress | 2 Simply Schedule Appointments, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions. | ||||
| CVE-2026-65515 | 2 Affiliatewp, Wordpress | 2 Affiliatewp, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions. | ||||
| CVE-2026-65547 | 2 Constantcontact, Wordpress | 2 Creative Mail, Wordpress | 2026-08-06 | 8.5 High |
| Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | ||||
| CVE-2026-65549 | 2026-08-06 | 7.2 High | ||
| Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions. | ||||
| CVE-2026-65565 | 2 Ays-pro, Wordpress | 2 Survey Maker, Wordpress | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Survey Maker <= 5.2.3.3 versions. | ||||
| CVE-2026-65569 | 2 Wordpress, Wpjobportal | 2 Wordpress, Wp Job Portal | 2026-08-06 | 8.5 High |
| Subscriber SQL Injection in WP Job Portal <= 2.5.6 versions. | ||||
| CVE-2026-61964 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Ninja Tables | 2026-08-06 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | ||||
| CVE-2026-67551 | 1 Apache | 2 Qpid Proton-dotnet, Qpid Proton Dotnet | 2026-08-06 | 7.5 High |
| pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue. | ||||
| CVE-2026-18510 | 2 Cozmoslabs, Wordpress | 2 Translatepress – Translate Multilingual Sites With Ai Translation, Wordpress | 2026-08-06 | 7.2 High |
| The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content (URL-encoded gettext markers) in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Comment moderation may delay exploitation for first-time commenters, but does not prevent it, as the payload uses only WordPress-permitted tags and attributes with percent-encoded characters that pass wp_kses URL validation unmodified. | ||||
| CVE-2025-11362 | 2 Pdfmake, Pdfmake Project | 2 Pdfmake, Pdfmake | 2026-08-06 | 7.5 High |
| Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding. An attacker can cause the application to crash or become unresponsive by providing crafted input that triggers this condition. | ||||
| CVE-2024-21549 | 1 Spatie | 1 Browsershot | 2026-08-06 | 8.6 High |
| Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file. **Note:** This is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745). | ||||