Total CVEs

150,604

Critical Severity

4,940

High Severity

17,474

Last 7 Days

2,190
Quick preset (or use dates below)
Clear Filters
Showing 1,301 - 1,320 of 150,604 CVEs
CVE-2026-13400 MEDIUM - 6.1

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: the rendered notification content is decoded back into live HTML after it has already passed through the Simply Sc...

Vendor: Unknown
Product: Simply Schedule Appointments
Published: Jul 27, 2026
Source: NVD
CVE-2026-13390 MEDIUM - 5.3

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing unauthenticated attackers to mark existing import records as failed and to store arb...

Vendor: Unknown
Product: The Events Calendar
Published: Jul 27, 2026
Source: NVD
CVE-2026-13332 CRITICAL - 9.1

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active sessions (force-logout) of any user on the site, including administrators.

Vendor: Unknown
Product: Masteriyo LMS
Published: Jul 27, 2026
Source: NVD
CVE-2026-13152 HIGH - 8.1

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted ...

Vendor: Unknown
Product: Custom Fields Account Registration For Woocommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-12982 MEDIUM - 6.1

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated AJAX action, leading to a Reflected Cross-Site Scripting vulnerability which can be exploited against unauthenticated users.

Vendor: Unknown
Product: Document Gallery
Published: Jul 27, 2026
Source: NVD
CVE-2026-12493 HIGH - 7.5

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid amount matches the order total, allowing unauthenticated users to mark arbitrary o...

Vendor: Unknown
Product: Clover Payment Gateway by Zaytech for WooCommerce
Published: Jul 27, 2026
Source: NVD
CVE-2026-12394 CRITICAL - 9.8

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

Vendor: Unknown
Product: MemberGlut
Published: Jul 27, 2026
Source: NVD
CVE-2026-12255 HIGH - 8.1

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that accoun...

Vendor: Unknown
Product: MainWP Child
Published: Jul 27, 2026
Source: NVD
CVE-2026-10082 MEDIUM - 6.1

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the Contributor role and above to inject arbitrary web scripts that execute when the affected content is viewed, including by higher-privileged us...

Vendor: Unknown
Product: Advanced Ads
Published: Jul 27, 2026
Source: NVD
CVE-2025-15662 HIGH - 8.6

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing unauthenticated attackers to read arbitrary local files (including configuration f...

Vendor: Unknown
Product: Printcart Web to Print Product Designer for WooCommerce
Published: Jul 27, 2026
Source: NVD

XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.

Vendor: XMLRPC-C
Product: XMLRPC-C
Published: Jul 27, 2026
Source: NVD
CVE-2026-17501 MEDIUM - 5.3

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This manipulation causes allocation of resources. The attack may be initiated remotely. The pull reque...

Vendor: ggml-org
Product: llama.cpp
Published: Jul 27, 2026
Source: NVD
CVE-2026-17500 MEDIUM - 5.3

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

Vendor: ggml-org
Product: llama.cpp
Published: Jul 27, 2026
Source: NVD
CVE-2026-57990 HIGH - 7.4

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Published: Jul 26, 2026
Source: NVD
CVE-2026-57989 HIGH - 7.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Published: Jul 26, 2026
Source: NVD
CVE-2026-57978 MEDIUM - 5.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Published: Jul 26, 2026
Source: NVD
CVE-2026-17497 HIGH - 8.3

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating ...

Vendor: codexu
Product: NoteGen
Published: Jul 26, 2026
Source: NVD
CVE-2026-17496 HIGH - 8.1

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a mal...

Vendor: codexu
Product: NoteGen
Published: Jul 26, 2026
Source: NVD
CVE-2026-17459 MEDIUM - 4.3

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible ...

Vendor: perwendel
Product: spark
Published: Jul 26, 2026
Source: NVD
CVE-2026-17458 MEDIUM - 6.3

A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. It is possible to initiate the attack re...

Vendor: mf-yang
Product: openclaw-cn
Published: Jul 26, 2026
Source: NVD