Export limit exceeded: 381577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 381577 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381577 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-75091 | 2 Mdmag, Wordpress | 2 Quill Forms | Conversational Multi Step Forms, Surveys & Quizzes, Wordpress | 2026-08-21 | 7.2 High |
| The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | ||||
| CVE-2026-75626 | 1 Smicallef | 1 Spiderfoot | 2026-08-21 | 9.3 Critical |
| SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys. | ||||
| CVE-2026-19447 | 1 Fileorbis | 1 Fileorbis | 2026-08-21 | 5.4 Medium |
| Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS. This issue affects FileOrbis: before 16.5. | ||||
| CVE-2026-15585 | 1 Akin | 1 Akinsoft Wolvox9 Erp / Kontrolpanel.exe | 2026-08-21 | 7.5 High |
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22. | ||||
| CVE-2026-5224 | 1 Kriptok Crypto | 1 Cryptosim | 2026-08-21 | 5.7 Medium |
| Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229. | ||||
| CVE-2026-16309 | 1 Netiket Information Technologies | 1 Edoweb | 2026-08-21 | 5.3 Medium |
| Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7. | ||||
| CVE-2026-50575 | 1 Unitronix | 1 Betterdesk | 2026-08-21 | 7.7 High |
| BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available. | ||||
| CVE-2026-28567 | 2 Fahad Mahmood, Wordpress | 2 Wp Sort Order, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions. | ||||
| CVE-2026-28570 | 2 Spabrice, Wordpress | 2 Vavo Core, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions. | ||||
| CVE-2026-32444 | 2 Cwicly, Wordpress | 2 Cwicly, Wordpress | 2026-08-21 | 9.9 Critical |
| Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | ||||
| CVE-2026-32463 | 2 Kamlesh Parmar, Wordpress | 2 Sync Post With Other Site, Wordpress | 2026-08-21 | 9.9 Critical |
| Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | ||||
| CVE-2026-32464 | 2 Vladimir Prelovac, Wordpress | 2 Theme Test Drive, Wordpress | 2026-08-21 | 8.1 High |
| Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. | ||||
| CVE-2026-32466 | 2 Wordpress, Wpexperts | 2 Wordpress, Gravity Forms Bookings Premium | 2026-08-21 | 8.5 High |
| Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | ||||
| CVE-2026-32467 | 2 Apoyl, Wordpress | 2 [aotuman] Grab Wechat Articles, Wordpress | 2026-08-21 | 6 Medium |
| Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | ||||
| CVE-2026-32472 | 2 Wbolt.com, Wordpress | 2 Online Contact Widget, Wordpress | 2026-08-21 | 7.5 High |
| Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | ||||
| CVE-2026-32473 | 2 Deknows, Wordpress | 2 Pdf Smart Viewer For Elementor, Wordpress | 2026-08-21 | 7.2 High |
| Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | ||||
| CVE-2026-32474 | 2 Wordpress, Wpwax | 2 Wordpress, Templatiq | 2026-08-21 | 9.9 Critical |
| Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | ||||
| CVE-2026-66620 | 2 Derek Herman, Wordpress | 2 Optiontree, Wordpress | 2026-08-21 | 7.2 High |
| Editor PHP Object Injection in OptionTree <= 2.7.3 versions. | ||||
| CVE-2026-66627 | 2 Edge22 Studios Ltd., Wordpress | 2 Gp Premium, Wordpress | 2026-08-21 | 9.9 Critical |
| Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions. | ||||
| CVE-2026-66633 | 2 Wordpress, Wpmanageninja | 2 Wordpress, Fluent Forms Pro Add On Pack | 2026-08-21 | 7.1 High |
| Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions. | ||||