01 Record index
CVE records
393,934 records indexed · sorted by most recently published
02 Records
CVE IDCVSSEPSSSeverityEXPLOITSummaryVendor / ProductPublished
CVE-2026-91019——Unrated—Event Booking Manager for WooCommerce < 5.6.0 - Contributor+ Payment Gateway Credential Disclosureunknown event booking manager for woocommerce35 MIN AGO
CVE-2026-91016——Unrated—Motors < 1.4.121 - Unauthenticated Draft/Private Listing Disclosureunknown motors35 MIN AGO
CVE-2026-91015——Unrated—Master Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expiredunknown master addons for elementor35 MIN AGO
CVE-2026-91014——Unrated—Realtyna Organic IDX plugin + WPL Real Estate < 5.4.2 - Reflected XSS via Location Selector Endpointunknown realtyna organic idx plugin + wpl real estate35 MIN AGO
CVE-2026-91011——Unrated—EWWW Image Optimizer < 8.7.7 - Author+ Stored XSS via Image Class Attribute Backreference Expansionunknown ewww image optimizer35 MIN AGO
CVE-2026-91010——Unrated—Invisible Anti-Spam & CAPTCHA < 5.1.1 - Subscriber+ Arbitrary Form Submission Deletionunknown invisible anti-spam & captcha — recaptcha alternative for all forms35 MIN AGO
CVE-2026-91009——Unrated—Active Products Tables for WooCommerce < 2.1.3 - Subscriber+ Arbitrary Post Title Modification via woot_update_attachmentunknown active woot products tables for woocommerce. 100% free35 MIN AGO
CVE-2026-91008——Unrated—Event Booking Manager for WooCommerce < 5.3.8 - Unauthenticated Attendee PII Disclosure via Booking Confirmation Panelunknown event booking manager for woocommerce35 MIN AGO
CVE-2026-90923——Unrated—Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and Deletionunknown autopay35 MIN AGO
CVE-2026-90922——Unrated—Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal Standard Amount and Currency Mismatchunknown paid membership subscriptions35 MIN AGO
CVE-2026-88904——Unrated—PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalationunknown puppyfw35 MIN AGO
CVE-2026-88795——Unrated—wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Tokenunknown wpshopgermany it-recht kanzlei35 MIN AGO
CVE-2026-88792——Unrated—Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Updateunknown dictionary35 MIN AGO
CVE-2026-87836——Unrated—Comments Import & Export 2.1.11 - 2.5.3 - Author+ Comment PII Disclosure via Exportunknown comments import & export35 MIN AGO
CVE-2026-87786——Unrated—Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinatesunknown dewa kirim35 MIN AGO
CVE-2026-86824——Unrated—Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Keyunknown newsletter35 MIN AGO
CVE-2026-86788——Unrated—HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tagunknown ht mega addons for elementor35 MIN AGO
CVE-2026-86710——Unrated—Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameterunknown login with qr35 MIN AGO
CVE-2026-86709——Unrated—The Pressengine <= 1.0 - Unauthenticated Authentication Bypassunknown the pressengine35 MIN AGO
CVE-2026-86707——Unrated—Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameterunknown private feed key35 MIN AGO
CVE-2026-86446——Unrated—LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST Endpointunknown learnpress35 MIN AGO
CVE-2026-85130——Unrated—WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logsunknown wplp cookie consent35 MIN AGO
CVE-2026-85128——Unrated—Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Requestunknown choose user role at registration35 MIN AGO
CVE-2025-15697——Unrated—Dictionary <= 1.0 - Reflected XSS via Multiple Parametersunknown dictionary35 MIN AGO
CVE-2026-877969.8—Critical—Multi Uploader for Gravity Forms <= 1.1.9 - Unauthenticated Arbitrary File Upload via Chunked File Uploadsh1zen multi uploader for gravity forms2 HR AGO
CVE-2026-879358.1—High—Paid Downloads <= 3.15 - Unauthenticated Arbitrary File Upload via 'paiddownloads_update_file' Actionichurakov paid downloads2 HR AGO
CVE-2026-252817.4—High—Allocation of Resources Without Limits or Throttling in OOBMqualcomm, inc. snapdragon2 HR AGO
CVE-2026-252787.8—High—Time-of-check Time-of-use (TOCTOU) Race Condition in Automotive Software platform based on QNXqualcomm, inc. snapdragon2 HR AGO
CVE-2025-596077.8—High—Untrusted Pointer Dereference in Windows Computequalcomm, inc. snapdragon2 HR AGO
CVE-2026-506044.9—Medium—Unauthenticated Access Vulnerability in NitroSense and PredatorSense Softwareacer acer agent service2 HR AGO
CVE-2026-506034.9—Medium—Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSenseacer acer agent service2 HR AGO
CVE-2026-928394.3—Medium—Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.canva canva2 HR AGO
CVE-2026-863116.4—Medium—Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.44 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes10web photo gallery by 10web – mobile-friendly image gallery2 HR AGO
CVE-2026-890645.3—Medium—All-in-One WP Migration and Backup <= 7.110 - Unauthenticated Insufficient Credential Protection via Authorization Basic Headerservmask all-in-one wp migration and backup4 HR AGO
CVE-2026-928387.8—High—GeoVision GV-Remote E-Map dll hijacking vulnerabilitygeovision inc. gv-remote e-map4 HR AGO
CVE-2026-815467.7—High—The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threatcanva affinity4 HR AGO
CVE-2026-65388——Unrated—A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. Thisapple containerization8 HR AGO
CVE-2026-615998.8—High—djust has an unauthenticated arbitrary module import via the WebSocket/SSE view-mount pathdjust-org djust8 HR AGO