Total CVEs

140,409

Critical Severity

3,747

High Severity

13,543

Last 7 Days

1,713
Quick preset (or use dates below)
Clear Filters
Showing 6,961 - 6,980 of 13,935 CVEs
CVE-2026-39706 MEDIUM - 5.3

Missing Authorization vulnerability in Netro Systems Make My Trivia trivialy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Make My Trivia: from n/a through <= 1.1.0.

Vendor: Netro Systems
Product: Make My Trivia
Published: Apr 08, 2026
Source: NVD
CVE-2026-39705 MEDIUM - 5.3

Missing Authorization vulnerability in Mulika Team MIPL WC Multisite Sync mipl-wc-multisite-sync allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MIPL WC Multisite Sync: from n/a through <= 1.4.4.

Vendor: Mulika Team
Product: MIPL WC Multisite Sync
Published: Apr 08, 2026
Source: NVD
CVE-2026-39704 MEDIUM - 5.3

Missing Authorization vulnerability in nfusionsolutions Precious Metals Automated Product Pricing &#8211; Pro precious-metals-automated-product-pricing-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Precious Metals Automated Product Pricing &#8...

Vendor: nfusionsolutions
Product: Precious Metals Automated Product Pricing &#8211; Pro
Published: Apr 08, 2026
Source: NVD
CVE-2026-39703 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbits WPBITS Addons For Elementor Page Builder wpbits-addons-for-elementor allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through <= 1.8.1.

Vendor: wpbits
Product: WPBITS Addons For Elementor Page Builder
Published: Apr 08, 2026
Source: NVD
CVE-2026-39702 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wealcoder Animation Addons for Elementor animation-addons-for-elementor allows DOM-Based XSS.This issue affects Animation Addons for Elementor: from n/a through <= 2.6.1.

Vendor: Wealcoder
Product: Animation Addons for Elementor
Published: Apr 08, 2026
Source: NVD
CVE-2026-39701 MEDIUM - 5.3

Missing Authorization vulnerability in Andrew ShopWP wpshopify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShopWP: from n/a through <= 5.2.4.

Vendor: Andrew
Product: ShopWP
Published: Apr 08, 2026
Source: NVD
CVE-2026-39700 MEDIUM - 5.3

Missing Authorization vulnerability in WPXPO WowOptin optin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowOptin: from n/a through <= 1.4.32.

Vendor: WPXPO
Product: WowOptin
Published: Apr 08, 2026
Source: NVD
CVE-2026-39699 MEDIUM - 5.3

Missing Authorization vulnerability in massiveshift AI Workflow Automation ai-workflow-automation-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Workflow Automation: from n/a through <= 1.4.2.

Vendor: massiveshift
Product: AI Workflow Automation
Published: Apr 08, 2026
Source: NVD
CVE-2026-39698 MEDIUM - 5.3

Missing Authorization vulnerability in PublisherDesk The Publisher Desk ads.txt the-publisher-desk-ads-txt allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Publisher Desk ads.txt: from n/a through <= 1.5.0.

Vendor: PublisherDesk
Product: The Publisher Desk ads.txt
Published: Apr 08, 2026
Source: NVD
CVE-2026-39697 MEDIUM - 5.3

Missing Authorization vulnerability in HBSS Technologies MAIO &#8211; The new AI GEO / SEO tool maio-the-new-ai-geo-seo-tool allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MAIO &#8211; The new AI GEO / SEO tool: from n/a through <= 6.2.8.

Vendor: HBSS Technologies
Product: MAIO &#8211; The new AI GEO / SEO tool
Published: Apr 08, 2026
Source: NVD
CVE-2026-39696 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elfsight Elfsight WhatsApp Chat CC elfsight-whatsapp-chat allows DOM-Based XSS.This issue affects Elfsight WhatsApp Chat CC: from n/a through <= 1.2.0.

Vendor: Elfsight
Product: Elfsight WhatsApp Chat CC
Published: Apr 08, 2026
Source: NVD
CVE-2026-39695 MEDIUM - 5.4

Server-Side Request Forgery (SSRF) vulnerability in podigee Podigee podigee allows Server Side Request Forgery.This issue affects Podigee: from n/a through <= 1.4.0.

Vendor: podigee
Product: Podigee
Published: Apr 08, 2026
Source: NVD
CVE-2026-39694 MEDIUM - 5.3

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through <= 1.6.10.2.

Vendor: NSquared
Product: Simply Schedule Appointments
Published: Apr 08, 2026
Source: NVD
CVE-2026-39693 MEDIUM - 5.9

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fesomia FSM Custom Featured Image Caption fsm-custom-featured-image-caption allows DOM-Based XSS.This issue affects FSM Custom Featured Image Caption: from n/a through <= 1.25.1.

Vendor: fesomia
Product: FSM Custom Featured Image Caption
Published: Apr 08, 2026
Source: NVD
CVE-2026-39692 MEDIUM - 6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows Stored XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.3.

Vendor: tagDiv
Product: tagDiv Composer
Published: Apr 08, 2026
Source: NVD
CVE-2026-39691 MEDIUM - 5.3

Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box โ€“ Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box โ€“ Bitcoin & Crypto Donations: from ...

Vendor: AdAstraCrypto
Product: Cryptocurrency Donation Box โ€“ Bitcoin & Crypto Donations
Published: Apr 08, 2026
Source: NVD
CVE-2026-39690 MEDIUM - 5.3

Missing Authorization vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Author Avatars List/Block: from n/a through <= 2.1.25.

Vendor: Paul Bearne
Product: Author Avatars List/Block
Published: Apr 08, 2026
Source: NVD
CVE-2026-39688 MEDIUM - 5.3

Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.

Vendor: Glowlogix
Product: WP Frontend Profile
Published: Apr 08, 2026
Source: NVD
CVE-2026-39687 MEDIUM - 5.3

Missing Authorization vulnerability in Rapid Car Check Rapid Car Check Vehicle Data free-vehicle-data-uk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rapid Car Check Vehicle Data: from n/a through <= 2.0.

Vendor: Rapid Car Check
Product: Rapid Car Check Vehicle Data
Published: Apr 08, 2026
Source: NVD
CVE-2026-39685 MEDIUM - 5.3

Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through <= 10.0.10.

Vendor: lvaudore
Product: The Moneytizer
Published: Apr 08, 2026
Source: NVD