87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,051–1,100 of 87,929 · page 22 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-97253 | CVE-2026-97253 CVSS 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue af… |
| CVE-2026-97251 | CVE-2026-97251 CVSS 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions. |
| CVE-2026-97250 | CVE-2026-97250 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. |
| CVE-2026-9725 | CVE-2026-9725 CVSS 9.1 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5… |
| CVE-2026-97249 | CVE-2026-97249 CVSS 5.3 | Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions. |
| CVE-2026-97248 | CVE-2026-97248 CVSS 9.8 | Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. |
| CVE-2026-97247 | CVE-2026-97247 CVSS 6.5 | Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions. |
| CVE-2026-97246 | CVE-2026-97246 CVSS 4.9 | Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions. |
| CVE-2026-97245 | CVE-2026-97245 CVSS 7.2 | Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions. |
| CVE-2026-97244 | CVE-2026-97244 CVSS 7.5 | Contributor Path Traversal in Creator LMS <= 1.2.19 versions. |
| CVE-2026-97243 | CVE-2026-97243 CVSS 5.4 | Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions. |
| CVE-2026-97242 | CVE-2026-97242 CVSS 6.8 | Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions. |
| CVE-2026-97241 | CVE-2026-97241 CVSS 7.5 | Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions. |
| CVE-2026-97240 | CVE-2026-97240 CVSS 7.5 | Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions. |
| CVE-2026-9724 | CVE-2026-9724 CVSS 4.3 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect… |
| CVE-2026-97239 | CVE-2026-97239 CVSS 6.5 | Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. |
| CVE-2026-97238 | CVE-2026-97238 CVSS 5.5 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. |
| CVE-2026-97237 | CVE-2026-97237 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. |
| CVE-2026-97236 | CVE-2026-97236 CVSS 6.5 | Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. |
| CVE-2026-97235 | CVE-2026-97235 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions. |
| CVE-2026-97233 | CVE-2026-97233 CVSS 3.5 | A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component… |
| CVE-2026-97232 | CVE-2026-97232 CVSS 6.3 | A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files… |
| CVE-2026-97231 | CVE-2026-97231 CVSS 7.3 | A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Inter… |
| CVE-2026-97230 | CVE-2026-97230 CVSS 9.8 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Py… |
| CVE-2026-9723 | CVE-2026-9723 CVSS 4.3 | The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing… |
| CVE-2026-97228 | CVE-2026-97228 CVSS 2.7 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status component (`get_export_status` in `src/exp… |
| CVE-2026-97227 | CVE-2026-97227 CVSS 5.9 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, rely… |
| CVE-2026-97226 | CVE-2026-97226 CVSS 6.3 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files… |
| CVE-2026-97225 | CVE-2026-97225 CVSS 6.3 | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON … |
| CVE-2026-97224 | CVE-2026-97224 CVSS 4.3 | A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file packages/excalidraw/data/restore.ts of the com… |
| CVE-2026-97222 | CVE-2026-97222 CVSS 5.5 | A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML pa… |
| CVE-2026-9722 | CVE-2026-9722 CVSS 4.3 | The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrec… |
| CVE-2026-97219 | CVE-2026-97219 CVSS 4.3 | The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a self-reg… |
| CVE-2026-97212 | CVE-2026-97212 CVSS 7.3 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifi… |
| CVE-2026-9721 | CVE-2026-9721 CVSS 4.3 | The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missi… |
| CVE-2026-97208 | CVE-2026-97208 | The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mi… |
| CVE-2026-9720 | CVE-2026-9720 CVSS 4.3 | The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is du… |
| CVE-2026-97197 | CVE-2026-97197 CVSS 7.5 | Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions. |
| CVE-2026-97196 | CVE-2026-97196 CVSS 9.1 | Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: fro… |
| CVE-2026-9719 | CVE-2026-9719 CVSS 4.3 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… |
| CVE-2026-97185 | CVE-2026-97185 CVSS 7.8 | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing … |
| CVE-2026-97182 | CVE-2026-97182 CVSS 7.3 | A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo… |
| CVE-2026-97181 | CVE-2026-97181 CVSS 5.3 | GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs. |
| CVE-2026-9718 | CVE-2026-9718 CVSS 6.5schneider-electric | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availabi… |
| CVE-2026-97179 | CVE-2026-97179 CVSS 4.3 | A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/sr… |
| CVE-2026-97177 | CVE-2026-97177 CVSS 6.6 | A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for sp… |
| CVE-2026-97176 | CVE-2026-97176 CVSS 4.2 | A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client s… |
| CVE-2026-9717 | CVE-2026-9717 CVSS 7.2schneider-electric | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of comman… |
| CVE-2026-97168 | CVE-2026-97168 | Rejected reason: it is a suggestion |
| CVE-2026-97165 | CVE-2026-97165 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” parameter is base64-decoded and written to… |