Export limit exceeded: 369862 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369862 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-27377 | 2026-07-23 | 6.7 Medium | ||
| Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | ||||
| CVE-2026-15448 | 2 Tickera, Wordpress | 2 Tickera – Sell Tickets & Manage Events, Wordpress | 2026-07-23 | 6.5 Medium |
| The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | ||||
| CVE-2026-65550 | 2026-07-23 | 5.9 Medium | ||
| Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | ||||
| CVE-2026-65539 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions. | ||||
| CVE-2026-65538 | 2026-07-23 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Machete <= 5.2 versions. | ||||
| CVE-2026-65537 | 2026-07-23 | 4.3 Medium | ||
| Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions. | ||||
| CVE-2026-65534 | 2026-07-23 | 5.9 Medium | ||
| Author Cross Site Scripting (XSS) in Custom links in Elementor Image Carousel <= 1.1.1 versions. | ||||
| CVE-2026-65533 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Smart SEO Tool <= 4.1.2 versions. | ||||
| CVE-2026-65527 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in LIQUID SPEECH BALLOON <= 1.2.5 versions. | ||||
| CVE-2026-65519 | 2026-07-23 | 6.5 Medium | ||
| Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. | ||||
| CVE-2026-65518 | 2026-07-23 | 6.5 Medium | ||
| Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions. | ||||
| CVE-2026-65516 | 2026-07-23 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-65510 | 2026-07-23 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-65506 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | ||||
| CVE-2026-65505 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions. | ||||
| CVE-2026-65501 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions. | ||||
| CVE-2026-65499 | 2026-07-23 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. | ||||
| CVE-2026-65498 | 2026-07-23 | 5.3 Medium | ||
| Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-65497 | 2026-07-23 | 7.2 High | ||
| Administrator PHP Object Injection in Complianz <= 7.5.0 versions. | ||||
| CVE-2026-65496 | 2026-07-23 | 4.4 Medium | ||
| Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions. | ||||