Total CVEs

140,343

Critical Severity

3,747

High Severity

13,518

Last 7 Days

1,769
Quick preset (or use dates below)
Clear Filters
Showing 6,281 - 6,300 of 13,903 CVEs
CVE-2026-3355 MEDIUM - 6.1

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘crsearch’ parameter in all versions up to, and including, 5.101.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj...

Published: Apr 16, 2026
Source: NVD
CVE-2026-1572 MEDIUM - 6.4

The Livemesh Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 9.0. This is due to missing authorization checks on the AJAX handler `lae_admin_ajax()` and insufficient...

Published: Apr 16, 2026
Source: NVD
CVE-2025-13364 MEDIUM - 6.4

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'put_wpgm' shortcode in all versions up to, and including, 4.8.7. This is due to insufficient input sanitization and output...

Vendor: flippercode
Product: WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
Published: Apr 16, 2026
Source: NVD
CVE-2026-3773 MEDIUM - 6.5

The Accessibility Suite by Ability, Inc plugin for WordPress is vulnerable to SQL Injection via the 'scan_id' parameter in all versions up to, and including, 4.20. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL que...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3595 MEDIUM - 5.3

The Riaxe Product Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.2. This is due to the plugin registering a REST API route at POST /wp-json/InkXEProductDesignerLite/customer/delete_customer without a permission_callback, causing WordPr...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3581 MEDIUM - 5.3

The Basic Google Maps Placemarks plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.10.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify stored...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3551 MEDIUM - 4.4

The Custom New User Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's admin settings in all versions up to, and including, 1.2.0. This is due to insufficient input sanitization and output escaping on multiple settings fields including 'User Mai...

Published: Apr 16, 2026
Source: NVD
CVE-2026-22618 MEDIUM - 5.9

A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available ...

Vendor: Eaton
Product: IPP software
Published: Apr 16, 2026
Source: NVD
CVE-2026-22617 MEDIUM - 5.7

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP software which is available on th...

Vendor: Eaton
Product: IPP Software
Published: Apr 16, 2026
Source: NVD
CVE-2026-40118 MEDIUM - 6.3

UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname of the affected product to a dummy URL, the product may unintentionally communicate with the dummy domain, causing information...

Vendor: Arcserve
Product: UDP Console
Published: Apr 16, 2026
Source: NVD
CVE-2026-22616 MEDIUM - 6.5

Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eaton IPP which is available on the Eaton download centre.

Vendor: Eaton
Product: IPP Software
Published: Apr 16, 2026
Source: NVD
CVE-2026-22615 MEDIUM - 6.0

Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious code resulting in arbitrary command execution. This security issue has been fixed in the latest version ...

Vendor: Eaton
Product: IPP Software
Published: Apr 16, 2026
Source: NVD
CVE-2023-5872 MEDIUM - 4.3

In Wago Smart Designer in versions up to 2.33.1 a low privileged remote attacker may enumerate projects and usernames through iterative requests to an specific endpoint.

Published: Apr 16, 2026
Source: NVD
CVE-2026-5070 MEDIUM - 6.4

The Vantage theme for WordPress is vulnerable to Stored Cross-Site Scripting via Gallery block text content in versions up to, and including, 1.20.32 due to insufficient output escaping in the gallery template. This makes it possible for authenticated attackers, with contributor-level access and abo...

Published: Apr 16, 2026
Source: NVD
CVE-2026-4032 MEDIUM - 6.1

The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in 'cc' comment shortcode in versions up to, and including, 0.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated at...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3878 MEDIUM - 6.4

The WP Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpdocs_options[icon_size]' parameter in all versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subsc...

Published: Apr 16, 2026
Source: NVD
CVE-2026-3885 MEDIUM - 6.4

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This...

Published: Apr 16, 2026
Source: NVD
CVE-2026-40962 MEDIUM - 4.9

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

Vendor: FFMpeg
Product: FFMpeg
Published: Apr 16, 2026
Source: NVD
CVE-2026-3299 MEDIUM - 6.4

The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode in all versions up to, and including, 1.7.29 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe...

Published: Apr 16, 2026
Source: NVD
CVE-2026-40353 MEDIUM - 5.4

wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) without escaping, and templates render the result using Django&#...

Vendor: pip
Product: wger
Published: Apr 16, 2026
Source: GitHub