Total CVEs

150,903

Critical Severity

5,032

High Severity

17,664

Last 7 Days

2,097
Quick preset (or use dates below)
Clear Filters
Showing 2,321 - 2,340 of 150,903 CVEs
CVE-2026-65469 MEDIUM - 5.3

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

Vendor: Strategy11 Team
Product: AWP Classifieds
Published: Jul 23, 2026
Source: NVD
CVE-2026-65468 MEDIUM - 5.3

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetBooking
Published: Jul 23, 2026
Source: NVD
CVE-2026-65467 MEDIUM - 4.9

Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetEngine
Published: Jul 23, 2026
Source: NVD
CVE-2026-65466 MEDIUM - 4.9

Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetBooking
Published: Jul 23, 2026
Source: NVD
CVE-2026-65465 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.

Vendor: Crocoblock. Jetimpex Inc.
Product: JetElements For Elementor
Published: Jul 23, 2026
Source: NVD
CVE-2026-65464 MEDIUM - 5.4

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

Vendor: Nexcess
Product: GiveWP
Published: Jul 23, 2026
Source: NVD
CVE-2026-65463 MEDIUM - 5.4

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

Vendor: masteriyo
Product: Masteriyo - LMS
Published: Jul 23, 2026
Source: NVD
CVE-2026-65462 HIGH - 7.6

Administrator SQL Injection in Uncanny Automator <= 7.3.2 versions.

Vendor: Uncanny Owl
Product: Uncanny Automator
Published: Jul 23, 2026
Source: NVD
CVE-2026-65461 CRITICAL - 9.1

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

Vendor: Webの相談所
Product: Really Simple CSV Importer
Published: Jul 23, 2026
Source: NVD
CVE-2026-65460 MEDIUM - 4.3

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

Vendor: zarinpal
Product: Zarinpal Gateway
Published: Jul 23, 2026
Source: NVD
CVE-2026-65458 MEDIUM - 4.3

Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions.

Vendor: Chouby
Product: Polylang
Published: Jul 23, 2026
Source: NVD
CVE-2026-65457 MEDIUM - 4.3

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

Vendor: yoomoney
Product: ЮKassa для WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-65456 MEDIUM - 4.3

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

Vendor: PickPlugins
Product: Product Slider for WooCommerce
Published: Jul 23, 2026
Source: NVD
CVE-2026-65455 CRITICAL - 9.1

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

Vendor: MapSVG
Product: MapSVG
Published: Jul 23, 2026
Source: NVD
CVE-2026-65454 HIGH - 8.5

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

Vendor: ExpressTech Systems
Product: Quiz And Survey Master
Published: Jul 23, 2026
Source: NVD
CVE-2026-65453 MEDIUM - 5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

Vendor: motov.net
Product: Ebook Store
Published: Jul 23, 2026
Source: NVD
CVE-2026-65452 MEDIUM - 5.3

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

Vendor: motov.net
Product: Ebook Store
Published: Jul 23, 2026
Source: NVD
CVE-2026-65451 HIGH - 8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

Vendor: RomanCode
Product: MapSVG
Published: Jul 23, 2026
Source: NVD
CVE-2026-65450 HIGH - 8.5

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

Vendor: RomanCode
Product: MapSVG
Published: Jul 23, 2026
Source: NVD
CVE-2026-65449 MEDIUM - 6.5

Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions.

Vendor: RomanCode
Product: MapSVG
Published: Jul 23, 2026
Source: NVD