Total CVEs

126,178

Critical Severity

2,292

High Severity

7,949

Last 7 Days

1,210
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,001 - 2,020 of 22,583 CVEs
CVE-2026-1395 MEDIUM - 6.4

The Gutentools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Slider block's block_id attribute in all versions up to, and including, 1.1.3. This is due to insufficient input sanitization and output escaping combined with a custom unescaping routine that reintrod...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6846 HIGH - 7.8

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6845 MEDIUM - 5.0

A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the syste...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6844 MEDIUM - 5.5

A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory c...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6843 MEDIUM - 5.5

A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Se...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6396 MEDIUM - 4.3

The Fast & Fancy Filter โ€“ 3F plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce verification in the saveFields() function, which handles the fff_save_settins AJAX action. This makes it possible for unauthenticated ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6294 MEDIUM - 4.3

The Google PageRank Display plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4. This is due to missing nonce validation in the gpdisplay_option() function, which handles the plugin settings page. The settings form does not include a wp_nonce_field(),...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6246 MEDIUM - 6.4

The Simple Random Posts Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'container_right_width' attribute of the 'simple_random_posts' shortcode in all versions up to, and including, 0.3 due to insufficient input sanitization and output escapin...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6236 MEDIUM - 6.4

The Posts map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' shortcode attribute in all versions up to, and including, 0.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6235 CRITICAL - 9.8

The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it pos...

Published: Apr 22, 2026
Source: NVD
CVE-2026-6041 MEDIUM - 4.4

The Buzz Comments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Custom Buzz Avatar' (buzz_comments_avatar_image) setting in all versions up to, and including, 0.9.4. This is due to insufficient input sanitization and output escaping. This makes it possible for ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-5820 MEDIUM - 6.4

The Zypento Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table of Contents block in all versions up to, and including, 1.0.6. This is due to the front-end TOC rendering script reading heading text via `innerText` and inserting it into the page using `innerHTML` wi...

Published: Apr 22, 2026
Source: NVD
CVE-2026-5767 MEDIUM - 6.4

The SlideShowPro SC plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `slideShowProSC` shortcode in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authen...

Published: Apr 22, 2026
Source: NVD
CVE-2026-5748 MEDIUM - 6.4

The Text Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ts` shortcode in all versions up to, and including, 0.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attack...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4353 MEDIUM - 6.4

The CI HUB Connector plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute of the `cihub_metadata` shortcode in all versions up to, and including, 1.2.106 due to insufficient input sanitization and output escaping. This makes it possible for authenticated...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4280 MEDIUM - 6.5

The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_ajax_form AJAX endpoint lacking both authorization checks and CSRF verification, combined with insufficient path validation when the brnwp_theme option ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4279 MEDIUM - 6.4

The Bread & Butter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'breadbutter-customevent-button' shortcode in all versions up to, and including, 8.2.0.25. This is due to insufficient input sanitization and output escaping on the 'event' shortcode ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4142 MEDIUM - 4.4

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Permanent keywords' field in all versions up to and including 1.0. This is due to insufficient input sanitization and output escaping. The plugin reads user input...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4140 MEDIUM - 4.3

The Ni WooCommerce Order Export plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 3.1.6. This is due to missing nonce validation in the ni_order_export_action() AJAX handler function. The handler processes settings updates when the 'page' ...

Published: Apr 22, 2026
Source: NVD
CVE-2026-4139 MEDIUM - 4.3

The mCatFilter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.5.2. This is due to the complete absence of nonce verification and capability checks in the compute_post() function, which processes settings updates. The compute_post() function is ...

Published: Apr 22, 2026
Source: NVD