Export limit exceeded: 404426 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 404426 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (404426 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-42709 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Food Menu – Restaurant Menu & Online Ordering for WooCommerce <= 6.0.5 versions. | ||||
| CVE-2026-42704 | 2026-10-11 | 8.1 High | ||
| Unauthenticated Local File Inclusion in Kids Care <= 3.2.4 versions. | ||||
| CVE-2026-42702 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Tutor LMS <= 4.1.0 versions. | ||||
| CVE-2026-42699 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in FV Player 8 <= 8.1.8 versions. | ||||
| CVE-2026-42697 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Social Share Icons & Social Share Buttons <= 3.7.5 versions. | ||||
| CVE-2026-42695 | 2026-10-11 | 6.5 Medium | ||
| Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Flowplayer Video Player fv-wordpress-flowplayer allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.54.7212. | ||||
| CVE-2026-42693 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Jannah <= 7.6.5 versions. | ||||
| CVE-2026-42633 | 2026-10-11 | 8.5 High | ||
| Subscriber SQL Injection in Events Manager <= 7.4.6 versions. | ||||
| CVE-2026-42632 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Qode Real Estate <= 1.1.7.3 versions. | ||||
| CVE-2026-42631 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Qode Music <= 2.1.8.2 versions. | ||||
| CVE-2026-42630 | 2026-10-11 | 7.5 High | ||
| Unauthenticated Sensitive Data Exposure in Web Plura Backup & Restore Manager <= 0.2.25 versions. | ||||
| CVE-2026-42419 | 2026-10-11 | 5.9 Medium | ||
| Unauthenticated Sensitive Data Exposure in Swish Migrate and Backup <= 1.4.0 versions. | ||||
| CVE-2026-40803 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Jotform – AI Chatbot <= 3.8.2 versions. | ||||
| CVE-2026-40800 | 2026-10-11 | 9.3 Critical | ||
| Subscriber SQL Injection in ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes <= 1.5.3 versions. | ||||
| CVE-2026-39800 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Additional Order Filters for WooCommerce <= 1.24 versions. | ||||
| CVE-2026-39799 | 2026-10-11 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in WP File Download <= 6.3.6 versions. | ||||
| CVE-2026-27350 | 1 Builderius.io | 1 Builderius | 2026-10-11 | 7.2 High |
| Server-Side Request Forgery (SSRF) vulnerability in Builderius.io Builderius allows Server Side Request Forgery. This issue affects Builderius: from 1.4 through 1.4-beta. | ||||
| CVE-2026-12980 | 2026-10-11 | 6.8 Medium | ||
| The Post Snippets WordPress plugin through 4.2.4 does not properly escape variable values substituted into snippets before outputting them, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the content is viewed. | ||||
| CVE-2026-107694 | 2026-10-11 | 2.7 Low | ||
| The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.2.0 does not verify that the vendor a commission calculation is requested for is the requesting vendor, allowing vendors to disclose the commission rate and fixed fee the marketplace administrator configured for other vendors. | ||||
| CVE-2026-105889 | 2026-10-11 | 9.3 Critical | ||
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6. | ||||