Total CVEs

132,167

Critical Severity

2,835

High Severity

10,137

Last 7 Days

1,639
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,641 - 3,660 of 28,572 CVEs
CVE-2026-6690 HIGH - 7.2

The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_mds AJAX action in all versions up to, and including, 2.2.2. This is due to the `wp_ajax_nopriv_lp_update_mds` action being registered without nonce verification or capabi...

Published: May 12, 2026
Source: NVD
CVE-2026-6663 MEDIUM - 4.8

The GWD Connect plugin for WordPress is vulnerable to missing authorization to limited code execution in all versions up to, and including, 2.9. This is due to the plugin's standalone agent endpoints (gwd-backup.php and gwd-logs.php) not verifying authentication when the API key has not been co...

Published: May 12, 2026
Source: NVD
CVE-2026-6402 MEDIUM - 5.3

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustwort...

Vendor: npm
Product: webpack-dev-server
Published: May 12, 2026
Source: NVD
CVE-2026-6256 MEDIUM - 6.4

The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes...

Published: May 12, 2026
Source: NVD
CVE-2026-6247 MEDIUM - 6.4

The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attribut...

Published: May 12, 2026
Source: NVD
CVE-2026-6237 MEDIUM - 6.4

The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po...

Published: May 12, 2026
Source: NVD
CVE-2026-5715 MEDIUM - 6.4

The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This mak...

Published: May 12, 2026
Source: NVD
CVE-2026-5693 MEDIUM - 5.3

The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation logic flaw in the saab_cancel_booking() function in all versions up to, and including, 1.0.8. The nonce check uses && (AND) ins...

Published: May 12, 2026
Source: NVD
CVE-2026-5340 MEDIUM - 6.4

The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show` shortcode in all versions up to, and including, 9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent...

Published: May 12, 2026
Source: NVD
CVE-2026-5028 MEDIUM - 6.5

The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and including, 1.2.6. This is due to insufficient escaping on the user supplied parameter and lack of...

Published: May 12, 2026
Source: NVD
CVE-2026-4920 MEDIUM - 6.4

The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a...

Published: May 12, 2026
Source: NVD
CVE-2026-4859 MEDIUM - 6.4

The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authen...

Published: May 12, 2026
Source: NVD
CVE-2026-4663 MEDIUM - 5.3

The iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3.7. This is due to the plugin exposing a REST API endpoint /wp-json/ipospays/v1/save_settings with 'permission_callback' set to '__return_true', which allows un...

Published: May 12, 2026
Source: NVD
CVE-2026-4301 MEDIUM - 4.3

The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. The vwrsr_review() AJAX handler lacks both capability checks and nonce verification. The only access control is an is_user_logged_in() ...

Published: May 12, 2026
Source: NVD
CVE-2026-3604 MEDIUM - 4.9

The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Co...

Published: May 12, 2026
Source: NVD
CVE-2026-39432 HIGH - 8.2

Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Timetics: from n/a through 1.0.53.

Vendor: Arraytics
Product: Timetics
Published: May 12, 2026
Source: NVD
CVE-2026-2993 HIGH - 7.5

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This ma...

Published: May 12, 2026
Source: NVD
CVE-2026-2300 MEDIUM - 6.4

The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and including, 1.0.9. This is due to the use of regex-based HTML processing (`preg_replace`) that does not properly handle HTML attribute boundaries when repla...

Published: May 12, 2026
Source: NVD

An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.

Vendor: CODESYS
Product: CODESYS Modbus
Published: May 12, 2026
Source: NVD
CVE-2026-1681 MEDIUM - 6.1

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input path on the same system work-queue stack. Because the destination is recognized as a local address, both the echo request and the resulting echo reply ...

Published: May 12, 2026
Source: NVD