Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
42,811 matching · page 101/857Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-73994(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. | Aug 18, 2026 |
| CVE-2026-73426(opens NVD record) | Medium | 4.6 | Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a data-trix-serialized-attributes attribute with a malicious payload that, when rendered, executes arbitrary JavaScript in the user's session and may perform unauthorized actions or disclose sensitive information. This issue is fixed in version 2.1.17. | Aug 18, 2026 |
| CVE-2026-73404(opens NVD record) | Medium | 6.5 | Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. | Aug 18, 2026 |
| CVE-2026-73400(opens NVD record) | High | 8.1 | Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. | Aug 18, 2026 |
| CVE-2026-73399(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. | Aug 18, 2026 |
| CVE-2026-73398(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. | Aug 18, 2026 |
| CVE-2026-73397(opens NVD record) | Critical | 9.8 | Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. | Aug 18, 2026 |
| CVE-2026-73396(opens NVD record) | High | 7.1 | Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions. | Aug 18, 2026 |
| CVE-2026-73395(opens NVD record) | Medium | 6.5 | Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions. | Aug 18, 2026 |
| CVE-2026-73393(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions. | Aug 18, 2026 |
| CVE-2026-73392(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions. | Aug 18, 2026 |
| CVE-2026-73383(opens NVD record) | Medium | 4.9 | Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions. | Aug 18, 2026 |
| CVE-2026-73382(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions. | Aug 18, 2026 |
| CVE-2026-73381(opens NVD record) | Critical | 9.1 | Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions. | Aug 18, 2026 |
| CVE-2026-73380(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions. | Aug 18, 2026 |
| CVE-2026-73379(opens NVD record) | Medium | 6.5 | Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions. | Aug 18, 2026 |
| CVE-2026-73378(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Contact Form by Supsystic < 1.10.0 versions. | Aug 18, 2026 |
| CVE-2026-73377(opens NVD record) | High | 7.5 | Unauthenticated Broken Access Control in Ultimate Maps by Supsystic < 1.5.0 versions. | Aug 18, 2026 |
| CVE-2026-73376(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions. | Aug 18, 2026 |
| CVE-2026-73375(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic < 1.5.0 versions. | Aug 18, 2026 |
| CVE-2026-73367(opens NVD record) | High | 7.2 | Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions. | Aug 18, 2026 |
| CVE-2026-73366(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions. | Aug 18, 2026 |
| CVE-2026-73365(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | Aug 18, 2026 |
| CVE-2026-73362(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in URL Shortify <= 2.5.0 versions. | Aug 18, 2026 |
| CVE-2026-73361(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | Aug 18, 2026 |
| CVE-2026-73360(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | Aug 18, 2026 |
| CVE-2026-73359(opens NVD record) | Medium | 6.5 | Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions. | Aug 18, 2026 |
| CVE-2026-73358(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Affiliates Manager <= 2.9.53 versions. | Aug 18, 2026 |
| CVE-2026-73356(opens NVD record) | High | 8.2 | Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions. | Aug 18, 2026 |
| CVE-2026-73355(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | Aug 18, 2026 |
| CVE-2026-73352(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions. | Aug 18, 2026 |
| CVE-2026-73351(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.1 versions. | Aug 18, 2026 |
| CVE-2026-73350(opens NVD record) | High | 8.2 | Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. | Aug 18, 2026 |
| CVE-2026-73348(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions. | Aug 18, 2026 |
| CVE-2026-73345(opens NVD record) | High | 7.1 | Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions. | Aug 18, 2026 |
| CVE-2026-73343(opens NVD record) | Critical | 10.0 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | Aug 18, 2026 |
| CVE-2026-73342(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions. | Aug 18, 2026 |
| CVE-2026-73341(opens NVD record) | Critical | 9.8 | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | Aug 18, 2026 |
| CVE-2026-73339(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | Aug 18, 2026 |
| CVE-2026-73338(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | Aug 18, 2026 |
| CVE-2026-73190(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | Aug 18, 2026 |
| CVE-2026-73189(opens NVD record) | Unscored | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-14858 | Aug 18, 2026 |
| CVE-2026-73187(opens NVD record) | Critical | 9.3 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | Aug 18, 2026 |
| CVE-2026-73181(opens NVD record) | High | 7.5 | Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions. | Aug 18, 2026 |
| CVE-2026-71539(opens NVD record) | Unscored | — | n8n is an open source workflow automation platform. Prior to 1.123.64, 2.29.8, and 2.30.1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server. This issue is fixed in versions 1.123.64, 2.29.8, and 2.30.1. | Aug 18, 2026 |
| CVE-2026-70657(opens NVD record) | Medium | 4.3 | Copyparty is a portable file server. Prior to 1.20.17, copyparty volumes with the dk or dks directory-key flag combined with the fk or fka file-key flag can convert a valid file key into a directory key, granting read access to the containing folder. This vulnerability was only reachable if both types of keys (filekeys and dirkeys) were manually enabled in the volume flags simultaneously. This issue is fixed in version 1.20.17. | Aug 18, 2026 |
| CVE-2026-69189(opens NVD record) | High | 7.6 | Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0. | Aug 18, 2026 |
| CVE-2026-68939(opens NVD record) | Unscored | — | Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-version-name, libexec/pyenv-which, libexec/pyenv-prefix, libexec/pyenv-local, libexec/pyenv-global, libexec/pyenv-version, and libexec/pyenv-versions pathname-expands the value against the current directory, allowing a matching attacker-controlled file to silently select a different installed interpreter or version. This issue is fixed in version 2.8.0. | Aug 18, 2026 |
| CVE-2026-68568(opens NVD record) | Medium | 6.3 | Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. | Aug 18, 2026 |
| CVE-2026-68567(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | Aug 18, 2026 |