21553 Total CVEs
12734 AI Analyzed
304 CISA KEV
4720 Critical
All Vendors
Showing 10951-11000 of 21553 CVEs Page 220 of 432
CVE-2026-15052
Analyzed
7.2
WordPress MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Fi...

2026-08-02
CVE-2026-1505
7.2
D-Link Multiple Products

A vulnerability was found in D-Link DIR-615 4

2026-01-28
CVE-2026-15048
Analyzed
7.5
WordPress Geeky Bot

The Geeky Bot WordPress plugin before 1

2026-08-01
CVE-2026-15043
Analyzed
9.8
HMBRAND DBI::SQL::Nano

DBI::SQL::Nano for Perl incorrectly evaluates SQL WHERE predicates, leading to inverted comparisons for <= and >= operators.

2026-07-15
CVE-2026-15039
Analyzed
9.8
WordPress giftware

The giftware WordPress plugin contains an unrestricted file upload vulnerability, allowing unauthenticated users to upload malicious files and execute...

2026-08-13
CVE-2026-15038
Analyzed
9.8
WordPress InfiniteWP Client

The InfiniteWP Client WordPress plugin fails to verify request authenticity, allowing unauthenticated attackers to hijack administrator sessions and a...

2026-08-18
CVE-2026-15017
Analyzed
8.8
WordPress MDJM Event Management

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1

2026-07-24
CVE-2026-15015
Analyzed
9.8
WordPress MountDev AI MCP Connector for WordPress

The MountDev AI MCP Connector plugin for WordPress contains an authorization bypass flaw that allows unauthenticated attackers to obtain administrativ...

2026-07-24
CVE-2026-15014
Analyzed
9.8
WordPress SMS Alert – SMS & OTP for WooCommerce

The SMS Alert plugin for WordPress is vulnerable to authentication bypass and account takeover due to an insecure OTP validation process that fails to...

2026-07-28
CVE-2026-15013
Analyzed
9.8
WordPress SAML Single Sign On – SSO Login

The SAML SSO plugin for WordPress is vulnerable to signature algorithm confusion, allowing unauthenticated attackers to forge assertions and gain admi...

2026-07-16
CVE-2026-15011
Analyzed
9.8
HP Customer Support Ticket System & Helpdesk

The Customer Support Ticket System & Helpdesk WordPress plugin is vulnerable to unauthenticated code injection via the path parameter, allowing attack...

2026-07-24
CVE-2026-15008
Analyzed
8.1
WordPress Uncanny Automator

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion...

2026-07-17
CVE-2026-15006
Analyzed
7.5
WordPress Bit Integrations

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal...

2026-08-01
CVE-2026-15005
Analyzed
8.8
WordPress Loco Translate

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2

2026-07-16
CVE-2026-15002
Analyzed
7.2
WordPress Autopay (platnosci-online-blue-media)

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5

2026-08-16
CVE-2026-15001
Analyzed
8.8
WordPress bLoyal: Loyalty & Promotions by bLoyal

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3

2026-08-15
CVE-2026-14996
Analyzed
8.2
IBM Aspera Faspex 5

IBM Aspera Faspex 5 5

2026-07-29
CVE-2026-1499
Analyzed
9.8
WordPress is vulnerable

The WP Duplicate plugin for WordPress allows authenticated subscribers to trigger a chain of vulnerabilities leading to unauthenticated remote code ex...

2026-02-06
CVE-2026-14980
Analyzed
8.3
IBM WebSphere Application Server - Liberty

IBM WebSphere Application Server - Liberty 17

2026-07-31
CVE-2026-14974
Analyzed
8.1
IBM WebSphere Application Server

IBM WebSphere Application Server 8

2026-07-29
CVE-2026-14960
9.8
Pegatron Tdelo64.sys

Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including...

2026-07-21
CVE-2026-14956
Analyzed
9.8
WordPress Bricksforge

The Bricksforge WordPress plugin contains a privilege escalation vulnerability in the Pro Forms component, allowing unauthenticated attackers to regis...

2026-07-17
CVE-2026-14948
Analyzed
8.8
Frauscher FDS 102

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live pla...

2026-08-20
CVE-2026-14943
Analyzed
7.5
WordPress Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API acce...

2026-08-15
CVE-2026-14934
Analyzed
9.4
Google BigQuery, Dataform, Colab Enterprise

Google Cloud BigQuery, Dataform, and Colab Enterprise contained a missing authorization vulnerability that allowed authenticated attackers to perform...

2026-07-14
CVE-2026-14930
Analyzed
7.5
WordPress JS Help Desk

The JS Help Desk WordPress plugin before 3

2026-08-01
CVE-2026-14924
Analyzed
7.5
WordPress Tablesome Table

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allow...

2026-08-04
CVE-2026-1492
Analyzed
9.8
WordPress is vulnerable

The RegistrationMagic WordPress plugin allows unauthenticated attackers to create administrator accounts by exploiting improper privilege management d...

2026-03-03
CVE-2026-14919
Analyzed
9.8
WordPress ShopMonitor.io WordPress Plugin

A critical authentication bypass in the ShopMonitor.io WordPress plugin allows unauthenticated attackers to hijack administrator accounts via email re...

2026-08-01
CVE-2026-14900
Analyzed
9.8
HP Cost Calculator Builder PRO

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to remote code execution via insufficient sanitization of input passed to a PHP eva...

2026-07-30
CVE-2026-1490
Analyzed
9.8
WordPress is vulnerable

The CleanTalk Anti-Spam plugin for WordPress allows unauthenticated attackers to install arbitrary plugins via PTR record spoofing, potentially leadin...

2026-02-15
CVE-2026-14895
Analyzed
7.5
BAKERSCOT String::Util

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing...

2026-07-11
CVE-2026-14894
Analyzed
9.8
WordPress Super Forms – Drag & Drop Form Builder

The Super Forms plugin for WordPress suffers from an unauthenticated arbitrary file upload vulnerability via the `submit_form` AJAX handler, enabling...

2026-07-10
CVE-2026-14891
Analyzed
8.7
Docker Nomad

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host...

2026-07-09
CVE-2026-14886
Analyzed
8.2
HashiCorp Vault Enterprise

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated calle...

2026-08-11
CVE-2026-14881
Analyzed
7.8
MongoDB MongoDB Compass

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form

2026-07-24
CVE-2026-14871
Analyzed
7.1
GitHub osTicket

osTicket versions v1

2026-07-19
CVE-2026-14870
7.1
WordPress Database for Contact Form 7, WPforms, Elementor forms

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before refle...

2026-08-18
CVE-2026-14869
Analyzed
8.6
HashiCorp Terraform MCP Server

The terraform-mcp-server before version 1

2026-07-29
CVE-2026-14868
Analyzed
8.4
ARC Informatique PcVue

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions pri...

2026-07-08
CVE-2026-14863
Analyzed
8.8
FileRun FileRun

FileRun up to and including version 2026

2026-08-12
CVE-2026-1486
8.8
Unknown Multiple Products

A flaw was found in Keycloak

2026-02-10
CVE-2026-14837
Analyzed
7.8
Lenze c430, c520, c550, i950 GenA, i950 GenB

Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism

2026-07-27
CVE-2026-14830
Analyzed
7.5
WordPress FlxWoo

The FlxWoo WordPress plugin before 3

2026-08-01
CVE-2026-14829
Analyzed
8.2
WordPress Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps

The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1

2026-08-06
CVE-2026-14812
Analyzed
10
WordPress Premium SEO

The Premium SEO WordPress plugin contains a malicious backdoor that enables unauthenticated attackers to create admin accounts, execute code, and inje...

2026-08-07
CVE-2026-14809
Analyzed
7.5
PROG MIS Prog Management System

Prog Management System developed by PROG MIS has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL comm...

2026-07-06
CVE-2026-14808
Analyzed
9.8
PROG MIS Prog Management System

The PROG MIS Prog Management System contains an information exposure vulnerability that allows unauthenticated remote attackers to view sensitive data...

2026-07-06
CVE-2026-14807
Analyzed
9.8
PROG MIS ERP App

The PROG MIS ERP App contains a hard-coded credentials vulnerability, allowing unauthenticated remote attackers to access application code and comprom...

2026-07-06
CVE-2026-14804
Analyzed
9.1
Unknown HUMANIST Digital Human Resources

Bilin Software and Informatics Consultancy HUMANIST Digital Human Resources versions 26.0 before 26.1 contain a hard-coded cryptographic key, allowing...

2026-08-04