Total CVEs

138,770

Critical Severity

3,601

High Severity

12,907

Last 7 Days

1,529
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,401 - 2,420 of 13,080 CVEs
CVE-2026-40825 MEDIUM - 5.5

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view devices parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. Thi...

Vendor: MB connect line, Helmholz
Product: mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: May 27, 2026
Source: NVD
CVE-2026-40824 MEDIUM - 5.5

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view userid parameter due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This...

Vendor: MB connect line, Helmholz
Product: mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: May 27, 2026
Source: NVD
CVE-2026-40823 MEDIUM - 5.5

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset function due to improper neutralization of special elements in a SQL UPDATE command allowing for reading the whole database and changing values in a non critical table. This can result ...

Vendor: MB connect line, Helmholz
Product: mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: May 27, 2026
Source: NVD
CVE-2026-40822 MEDIUM - 4.9

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Vendor: MB connect line, Helmholz
Product: mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: May 27, 2026
Source: NVD
CVE-2026-40821 MEDIUM - 4.9

A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

Vendor: MB connect line, Helmholz
Product: mbCONNECT24, mymbCONNECT24, myREX24V2, myREX24V2.virtual
Published: May 27, 2026
Source: NVD
CVE-2026-3897 MEDIUM - 6.4

The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but do...

Published: May 27, 2026
Source: NVD
CVE-2026-3896 MEDIUM - 6.4

The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lsow_admin_ajax` AJAX action in all versions up to, and including, 3.9.2 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce but does not ...

Published: May 27, 2026
Source: NVD
CVE-2026-3895 MEDIUM - 6.4

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `lvca_admin_ajax` AJAX action in all versions up to, and including, 3.9.4 due to missing authorization checks and insufficient input sanitization. The AJAX handler verifies a nonce ...

Published: May 27, 2026
Source: NVD
CVE-2026-3279 MEDIUM - 6.5

The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `downgrade_jquery_version()` function in all versions up to, and including, 1.4.1. This is due to the function only verifying a nonce without checking use...

Published: May 27, 2026
Source: NVD
CVE-2026-3001 MEDIUM - 6.1

The Gutenverse plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. Specifically, the `render_content()` method in `class-search-result-title.php` o...

Published: May 27, 2026
Source: NVD
CVE-2026-2030 MEDIUM - 6.4

The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[lvca_carousel]` and `[lvca_posts_carousel]` shortcode attributes in all versions up to, and including, 3.9.4 due to insufficient input sanitization and output escaping. Specifical...

Published: May 27, 2026
Source: NVD
CVE-2026-9014 MEDIUM - 5.3

The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_stats() function in versions up to, and including, 1.3. The function is hooked to both the wp_ajax_wpp-reset_stats and wp_ajax_nopriv_wpp-reset_stats actions and con...

Published: May 27, 2026
Source: NVD
CVE-2026-8943 MEDIUM - 4.3

The GoStats for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on the gostats_manage() function. This makes it possible for unauthenticated attackers to update the plugin'...

Published: May 27, 2026
Source: NVD
CVE-2026-8941 MEDIUM - 4.3

The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the ossdl_off_options() function. This makes it possible for unauthenticated attackers to update the plugin's set...

Published: May 27, 2026
Source: NVD
CVE-2026-8939 MEDIUM - 4.3

The Search Simple Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the search_simple_fields_options() function in functions_admin.php. This makes it possible for unauthenticated atta...

Published: May 27, 2026
Source: NVD
CVE-2026-8938 MEDIUM - 4.3

The auto making JSON-LD plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.3. This is due to missing or incorrect nonce validation on the amJL_certification function. This makes it possible for unauthenticated attackers to update the plugin...

Published: May 27, 2026
Source: NVD
CVE-2026-8911 MEDIUM - 6.1

The WP AutoBuzz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts v...

Published: May 27, 2026
Source: NVD
CVE-2026-8903 MEDIUM - 4.3

The Two-factor authentication (formerly IP Vault) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1. This is due to missing or incorrect nonce validation on the ipv_save_changes function. This makes it possible for unauthenticated attackers to...

Published: May 27, 2026
Source: NVD
CVE-2026-8899 MEDIUM - 6.4

The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on the shortcode's 'width' and 'height'...

Published: May 27, 2026
Source: NVD
CVE-2026-8898 MEDIUM - 6.4

The Events In City plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'org-events' shortcode in versions up to, and including, 3.0. This is due to insufficient input sanitization and output escaping on user supplied attributes (such as 'organizer_id', '...

Published: May 27, 2026
Source: NVD