Total CVEs

149,824

Critical Severity

4,834

High Severity

17,268

Last 7 Days

2,960
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 81 - 100 of 46,229 CVEs

Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code and potentially displaying harmful content on the affected screen.

Vendor: EShare
Product: ESharePro
Published: Jul 28, 2026
Source: NVD
CVE-2026-15730 MEDIUM - 6.4

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization ...

Vendor: rubengc
Product: GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
Published: Jul 28, 2026
Source: NVD
CVE-2026-15673 MEDIUM - 4.4

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via 'checkout_payment_plans' and 'order_status' Settings in all versions up to, and including, 3.9.7 due to insufficient es...

Vendor: cozyvision1
Product: SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
Published: Jul 28, 2026
Source: NVD
CVE-2026-15671 MEDIUM - 4.9

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to generic SQL Injection via the 'id' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied parameter and la...

Vendor: cozyvision1
Product: SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
Published: Jul 28, 2026
Source: NVD
CVE-2026-15670 MEDIUM - 4.9

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.9.7 due to insufficient escaping on the user supplied paramete...

Vendor: cozyvision1
Product: SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
Published: Jul 28, 2026
Source: NVD
CVE-2026-15014 CRITICAL - 9.8

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 3.9.7 via the `billing_phone` parameter. This is due to the `processRegistrat...

Vendor: cozyvision1
Product: SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
Published: Jul 28, 2026
Source: NVD
CVE-2026-12741 HIGH - 7.5

The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and including, 1.80.280 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation ...

Vendor: epsiloncool
Product: WP Fast Total Search – The Power of Indexed Search
Published: Jul 28, 2026
Source: NVD
CVE-2026-11756 CRITICAL - 10.0

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code execution.

Vendor: Dassault Systèmes
Product: Station Launcher App in 3DEXPERIENCE platform
Published: Jul 28, 2026
Source: NVD

In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficients by the modulus q: Poly.toMsg, which decodes the decrypted message, and the ciphertext compression routines Poly.compressPoly and PolyVec.compressPolyVec. An attac...

Vendor: Legion of the Bouncy Castle Inc.
Product: BC-JAVA
Published: Jul 28, 2026
Source: NVD
CVE-2026-6251 MEDIUM - 6.5

The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via filter_input(INPUT_POST, ...) and directl...

Published: Jul 28, 2026
Source: NVD
CVE-2026-16811 MEDIUM - 4.9

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.4.5 due to insufficient escaping on the user supplied parameter and lack of suffi...

Vendor: devitemsllc
Product: ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
Published: Jul 28, 2026
Source: NVD
CVE-2026-16797 MEDIUM - 4.3

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.5 via the 'optionSection' parameter due to missing validation on a user controlled key. This makes ...

Vendor: devitemsllc
Product: ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin
Published: Jul 28, 2026
Source: NVD
CVE-2026-16587 MEDIUM - 4.3

The Advanced Form Integration β€” Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated...

Vendor: nasirahmed
Product: Advanced Form Integration β€” Connect Forms to 200+ Apps
Published: Jul 28, 2026
Source: NVD
CVE-2026-16585 HIGH - 7.2

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_sticker function in all versions up to, and including, 2.15.19. This makes it possible for authentica...

Vendor: wordplus
Product: Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots
Published: Jul 28, 2026
Source: NVD
CVE-2026-15136 MEDIUM - 4.3

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.3.7. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated a...

Vendor: wplegalpages
Product: WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
Published: Jul 28, 2026
Source: NVD
CVE-2026-15012 MEDIUM - 5.3

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ d...

Vendor: deveasel
Product: Demi – One Click Demo Import, Backup & Site Migration
Published: Jul 28, 2026
Source: NVD
CVE-2026-14926 MEDIUM - 4.2

The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting customer in several of its payment-method endpoints, allowing any authenticated customer to act on another customer's subscription (changing its payment method, or ...

Vendor: Unknown
Product: FluentCart A New Era of eCommerce
Published: Jul 28, 2026
Source: NVD
CVE-2026-14924 HIGH - 7.5

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

Vendor: Unknown
Product: Tablesome Table
Published: Jul 28, 2026
Source: NVD
CVE-2026-14870 HIGH - 7.1

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Vendor: Unknown
Product: Database for Contact Form 7, WPforms, Elementor forms
Published: Jul 28, 2026
Source: NVD

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access and above to delete arbitrary templates.

Vendor: Unknown
Product: Quiz and Survey Master (QSM)
Published: Jul 28, 2026
Source: NVD