Export limit exceeded: 369875 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (369875 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65480 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.
CVE-2026-65479 2026-07-23 5.4 Medium
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.
CVE-2026-27064 2026-07-23 9.1 Critical
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
CVE-2026-27377 2026-07-23 6.7 Medium
Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.
CVE-2026-15448 2 Tickera, Wordpress 2 Tickera – Sell Tickets & Manage Events, Wordpress 2026-07-23 6.5 Medium
The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with staff-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
CVE-2026-65538 2026-07-23 5.9 Medium
Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537 2026-07-23 4.3 Medium
Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65518 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Accept Donations with PayPal & Stripe <= 1.5.5 versions.
CVE-2026-65506 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
CVE-2026-65498 2026-07-23 5.3 Medium
Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.
CVE-2026-65491 2026-07-23 4.3 Medium
Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.
CVE-2026-65486 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.
CVE-2026-65485 2026-07-23 5.3 Medium
Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.
CVE-2026-65473 2026-07-23 6.5 Medium
Contributor Cross Site Scripting (XSS) in Virtue/Ascend/Pinnacle Toolkit <= 4.9.12 versions.
CVE-2026-65461 2026-07-23 9.1 Critical
Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
CVE-2026-65454 2026-07-23 8.5 High
Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.
CVE-2026-61947 2026-07-23 7.1 High
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
CVE-2026-59555 2026-07-23 10 Critical
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
CVE-2026-59542 2026-07-23 7.7 High
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
CVE-2026-59540 2026-07-23 9.8 Critical
Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.