Total CVEs

150,920

Critical Severity

5,034

High Severity

17,670

Last 7 Days

2,096
Quick preset (or use dates below)
Clear Filters
Showing 2,421 - 2,440 of 150,920 CVEs
CVE-2026-57397 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Coaching <= 3.9.2 versions.

Vendor: ThimPress.
Product: Coaching
Published: Jul 23, 2026
Source: NVD
CVE-2026-57384 MEDIUM - 6.5

Subscriber Cross Site Scripting (XSS) in WishList Member X <= 3.32.0 versions.

Vendor: Membership Software
Product: WishList Member X
Published: Jul 23, 2026
Source: NVD
CVE-2026-57374 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.7 versions.

Vendor: Wisetr INC.
Product: Funnel Kit Funnel Builder PRO
Published: Jul 23, 2026
Source: NVD
CVE-2026-57373 MEDIUM - 6.5

Customer Cross Site Scripting (XSS) in Funnel Kit Funnel Builder PRO <= 3.15.0.4 versions.

Vendor: Wisetr INC.
Product: Funnel Kit Funnel Builder PRO
Published: Jul 23, 2026
Source: NVD
CVE-2026-57370 HIGH - 7.1

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.9.1 versions.

Vendor: CODEPRESS IT Solutions LLC
Product: Visitor Traffic Real Time Statistics Pro
Published: Jul 23, 2026
Source: NVD
CVE-2026-57367 HIGH - 7.1

Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.

Vendor: WP Booking System .
Product: WP Booking System
Published: Jul 23, 2026
Source: NVD
CVE-2026-27423 MEDIUM - 4.3

Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

Vendor: Roland Barker
Product: Participants Database
Published: Jul 23, 2026
Source: NVD
CVE-2026-27422 MEDIUM - 5.3

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

Vendor: bPlugins
Product: YT Player
Published: Jul 23, 2026
Source: NVD
CVE-2026-27418 MEDIUM - 5.3

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

Vendor: Epsiloncool
Product: WP Fast Total Search
Published: Jul 23, 2026
Source: NVD
CVE-2026-27403 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NerdPress Hubbub Lite allows Stored XSS. This issue affects Hubbub Lite: from n/a through 1.36.3.

Vendor: NerdPress
Product: Hubbub Lite
Published: Jul 23, 2026
Source: NVD
CVE-2026-27399 MEDIUM - 5.3

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

Vendor: WebWizards
Product: MarketKing
Published: Jul 23, 2026
Source: NVD
CVE-2026-27392 MEDIUM - 4.3

Contributor Broken Access Control in uListing <= 2.2.0 versions.

Vendor: Stylemix
Product: uListing
Published: Jul 23, 2026
Source: NVD
CVE-2026-27391 MEDIUM - 5.4

Subscriber Broken Access Control in uListing <= 2.2.0 versions.

Vendor: Stylemix
Product: uListing
Published: Jul 23, 2026
Source: NVD
CVE-2026-27377 MEDIUM - 6.7

Booking Agent Broken Access Control in QuickCal - Appointment Booking Calendar for WordPress <= 1.0.16 versions.

Vendor: axiomthemes
Product: QuickCal - Appointment Booking Calendar for WordPress
Published: Jul 23, 2026
Source: NVD
CVE-2026-27372 MEDIUM - 6.5

Unauthenticated Sensitive Data Exposure in PeproDev Ultimate Invoice <= 2.2.6 versions.

Vendor: Pepro Dev. Group
Product: PeproDev Ultimate Invoice
Published: Jul 23, 2026
Source: NVD
CVE-2026-27355 MEDIUM - 5.3

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

Vendor: metaphorcreations
Product: Ditty
Published: Jul 23, 2026
Source: NVD
CVE-2026-27064 CRITICAL - 9.1

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

Vendor: EverPress
Product: Mailster
Published: Jul 23, 2026
Source: NVD
CVE-2026-25466 MEDIUM - 5.3

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

Vendor: WPGMaps
Product: WP Go Maps
Published: Jul 23, 2026
Source: NVD
CVE-2026-25427 MEDIUM - 5.4

Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

Vendor: DigitalME
Product: eRoom
Published: Jul 23, 2026
Source: NVD
CVE-2026-25424 MEDIUM - 4.3

Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

Vendor: mediavine
Product: Mediavine Control Panel
Published: Jul 23, 2026
Source: NVD