Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
39,390 matching · page 353/788Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-57701(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | Jul 23, 2026 |
| CVE-2026-57699(opens NVD record) | High | 7.1 | Subscriber Cross Site Scripting (XSS) in Slider Pro <= 4.8.13 versions. | Jul 23, 2026 |
| CVE-2026-57696(opens NVD record) | High | 7.1 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | Jul 23, 2026 |
| CVE-2026-57626(opens NVD record) | High | 7.1 | Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | Jul 23, 2026 |
| CVE-2026-57428(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. | Jul 23, 2026 |
| CVE-2026-57427(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | Jul 23, 2026 |
| CVE-2026-57425(opens NVD record) | Medium | 6.5 | Unauthenticated Broken Access Control in Autopay dla WooCommerce <= 2.2.27 versions. | Jul 23, 2026 |
| CVE-2026-57397(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions. | Jul 23, 2026 |
| CVE-2026-57384(opens NVD record) | Medium | 6.5 | Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions. | Jul 23, 2026 |
| CVE-2026-57374(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions. | Jul 23, 2026 |
| CVE-2026-57373(opens NVD record) | Medium | 6.5 | Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions. | Jul 23, 2026 |
| CVE-2026-57370(opens NVD record) | High | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions. | Jul 23, 2026 |
| CVE-2026-57367(opens NVD record) | High | 7.1 | Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions. | Jul 23, 2026 |
| CVE-2026-27423(opens NVD record) | Medium | 4.3 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | Jul 23, 2026 |
| CVE-2026-27422(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions. | Jul 23, 2026 |
| CVE-2026-27418(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions. | Jul 23, 2026 |
| CVE-2026-27403(opens NVD record) | Medium | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3. | Jul 23, 2026 |
| CVE-2026-27399(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions. | Jul 23, 2026 |
| CVE-2026-27392(opens NVD record) | Medium | 4.3 | Contributor Broken Access Control in uListing <= 2.2.0 versions. | Jul 23, 2026 |
| CVE-2026-27391(opens NVD record) | Medium | 5.4 | Subscriber Broken Access Control in uListing <= 2.2.0 versions. | Jul 23, 2026 |
| CVE-2026-27377(opens NVD record) | Medium | 6.7 | Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions. | Jul 23, 2026 |
| CVE-2026-27372(opens NVD record) | Medium | 6.5 | Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions. | Jul 23, 2026 |
| CVE-2026-27355(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions. | Jul 23, 2026 |
| CVE-2026-27064(opens NVD record) | Critical | 9.1 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | Jul 23, 2026 |
| CVE-2026-25466(opens NVD record) | Medium | 5.3 | Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions. | Jul 23, 2026 |
| CVE-2026-25427(opens NVD record) | Medium | 5.4 | Subscriber Broken Access Control in eRoom <= 1.7.1 versions. | Jul 23, 2026 |
| CVE-2026-25424(opens NVD record) | Medium | 4.3 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | Jul 23, 2026 |
| CVE-2026-25405(opens NVD record) | High | 8.5 | Contributor SQL Injection in eRoom <= 1.7.1 versions. | Jul 23, 2026 |
| CVE-2026-24639(opens NVD record) | Medium | 4.4 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. | Jul 23, 2026 |
| CVE-2026-24628(opens NVD record) | Medium | 5.9 | Administrator Cross Site Scripting (XSS) in Photo Gallery by Supsystic <= 1.16.3 versions. | Jul 23, 2026 |
| CVE-2026-24552(opens NVD record) | High | 8.5 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'Allier Create allows Blind SQL Injection. This issue affects Create: from n/a through 2.5.3. | Jul 23, 2026 |
| CVE-2026-24537(opens NVD record) | Medium | 4.3 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions. | Jul 23, 2026 |
| CVE-2025-68081(opens NVD record) | Medium | 5.9 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. | Jul 23, 2026 |
| CVE-2026-64611(opens NVD record) | High | 7.5 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service. | Jul 23, 2026 |
| CVE-2026-16745(opens NVD record) | High | 8.8 | A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbitrary access token. This allows an attacker to gain unauthorized access to the Kubernetes API, potentially leading to arbitrary code execution, privilege escalation, or information disclosure. | Jul 23, 2026 |
| CVE-2026-65758(opens NVD record) | Unscored | — | Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions. | Jul 23, 2026 |
| CVE-2026-65757(opens NVD record) | High | 8.1 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens. | Jul 23, 2026 |
| CVE-2026-65756(opens NVD record) | Medium | 6.1 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. | Jul 23, 2026 |
| CVE-2026-65755(opens NVD record) | High | 7.5 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable. | Jul 23, 2026 |
| CVE-2026-65754(opens NVD record) | High | 7.5 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory. | Jul 23, 2026 |
| CVE-2026-65713(opens NVD record) | Medium | 6.5 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. | Jul 23, 2026 |
| CVE-2026-65712(opens NVD record) | Medium | 6.2 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata. | Jul 23, 2026 |
| CVE-2026-65431(opens NVD record) | Critical | 9.8 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions. | Jul 23, 2026 |
| CVE-2026-65430(opens NVD record) | High | 7.5 | Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability. | Jul 23, 2026 |
| CVE-2026-64876(opens NVD record) | High | 8.8 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates. | Jul 23, 2026 |
| CVE-2026-64875(opens NVD record) | Medium | 6.5 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass. | Jul 23, 2026 |
| CVE-2026-64874(opens NVD record) | Critical | 9.8 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. | Jul 23, 2026 |
| CVE-2026-64873(opens NVD record) | Critical | 9.8 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. | Jul 23, 2026 |
| CVE-2026-64872(opens NVD record) | Medium | 6.5 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory. | Jul 23, 2026 |
| CVE-2026-64871(opens NVD record) | Medium | 5.4 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission. | Jul 23, 2026 |