87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,051–1,100 of 87,929 · page 22 of 1759

IDTitleSummary
CVE-2026-97253CVE-2026-97253
CVSS 7.1
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue af…
CVE-2026-97251CVE-2026-97251
CVSS 6.5
Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.
CVE-2026-97250CVE-2026-97250
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-9725CVE-2026-9725
CVSS 9.1
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5…
CVE-2026-97249CVE-2026-97249
CVSS 5.3
Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.
CVE-2026-97248CVE-2026-97248
CVSS 9.8
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.
CVE-2026-97247CVE-2026-97247
CVSS 6.5
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
CVE-2026-97246CVE-2026-97246
CVSS 4.9
Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.
CVE-2026-97245CVE-2026-97245
CVSS 7.2
Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.
CVE-2026-97244CVE-2026-97244
CVSS 7.5
Contributor Path Traversal in Creator LMS <= 1.2.19 versions.
CVE-2026-97243CVE-2026-97243
CVSS 5.4
Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.
CVE-2026-97242CVE-2026-97242
CVSS 6.8
Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.
CVE-2026-97241CVE-2026-97241
CVSS 7.5
Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
CVE-2026-97240CVE-2026-97240
CVSS 7.5
Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
CVE-2026-9724CVE-2026-9724
CVSS 4.3
The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect…
CVE-2026-97239CVE-2026-97239
CVSS 6.5
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
CVE-2026-97238CVE-2026-97238
CVSS 5.5
Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
CVE-2026-97237CVE-2026-97237
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
CVE-2026-97236CVE-2026-97236
CVSS 6.5
Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
CVE-2026-97235CVE-2026-97235
CVSS 7.1
Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
CVE-2026-97233CVE-2026-97233
CVSS 3.5
A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component…
CVE-2026-97232CVE-2026-97232
CVSS 6.3
A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files…
CVE-2026-97231CVE-2026-97231
CVSS 7.3
A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Inter…
CVE-2026-97230CVE-2026-97230
CVSS 9.8
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Py…
CVE-2026-9723CVE-2026-9723
CVSS 4.3
The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing…
CVE-2026-97228CVE-2026-97228
CVSS 2.7
Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/exp…
CVE-2026-97227CVE-2026-97227
CVSS 5.9
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, rely…
CVE-2026-97226CVE-2026-97226
CVSS 6.3
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files…
CVE-2026-97225CVE-2026-97225
CVSS 6.3
A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON …
CVE-2026-97224CVE-2026-97224
CVSS 4.3
A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the com…
CVE-2026-97222CVE-2026-97222
CVSS 5.5
A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML pa…
CVE-2026-9722CVE-2026-9722
CVSS 4.3
The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrec…
CVE-2026-97219CVE-2026-97219
CVSS 4.3
The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-reg…
CVE-2026-97212CVE-2026-97212
CVSS 7.3
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifi…
CVE-2026-9721CVE-2026-9721
CVSS 4.3
The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missi…
CVE-2026-97208CVE-2026-97208The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mi…
CVE-2026-9720CVE-2026-9720
CVSS 4.3
The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is du…
CVE-2026-97197CVE-2026-97197
CVSS 7.5
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
CVE-2026-97196CVE-2026-97196
CVSS 9.1
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: fro…
CVE-2026-9719CVE-2026-9719
CVSS 4.3
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and…
CVE-2026-97185CVE-2026-97185
CVSS 7.8
A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing …
CVE-2026-97182CVE-2026-97182
CVSS 7.3
A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo…
CVE-2026-97181CVE-2026-97181
CVSS 5.3
GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.
CVE-2026-9718CVE-2026-9718
CVSS 6.5schneider-electric
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availabi…
CVE-2026-97179CVE-2026-97179
CVSS 4.3
A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/sr…
CVE-2026-97177CVE-2026-97177
CVSS 6.6
A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for sp…
CVE-2026-97176CVE-2026-97176
CVSS 4.2
A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client s…
CVE-2026-9717CVE-2026-9717
CVSS 7.2schneider-electric
CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of comman…
CVE-2026-97168CVE-2026-97168Rejected reason: it is a suggestion
CVE-2026-97165CVE-2026-97165Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.