CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 1501–1550 (page 31 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-95515 |
WordPress Ninja Forms plugin <= 3.15.3 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95514 |
WordPress Netgsm plugin <= 2.10.0 - Bypass Vulnerability vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-95513 |
WordPress Online Booking & Scheduling Calendar for WordPress by vcita plugin <= 4.6.0 - Broken Access Control vulnerabil… | HIGH | 7.5 | 7.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94684 |
WordPress Ocean Extra plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94682 |
WordPress Podcast Importer SecondLine plugin <= 1.5.6 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94680 |
WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94679 |
WordPress Fluent Support plugin <= 2.3.2 - Broken Access Control vulnerability | MEDIUM | 5.4 | 5.4 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94671 |
WordPress The Post Grid plugin <= 7.9.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94500 |
WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94498 |
WordPress AppMySite plugin <= 3.15.4 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94487 |
WordPress PublishPress Capabilities plugin <= 2.50.1 - Cross Site Request Forgery (CSRF) vulnerability | HIGH | 8.1 | 8.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94461 |
WordPress Ditty plugin <= 3.1.69 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94457 |
WordPress Captcha Code plugin <= 3.32 - Bypass Vulnerability vulnerability | MEDIUM | 4.8 | 4.8 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94391 |
WordPress Ultimate FAQ plugin <= 2.4.14 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94179 |
WordPress Razorpay Payment Button plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94176 |
WordPress Mang Board WP plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94174 |
WordPress Email Log plugin <= 2.63 - SQL Injection vulnerability | HIGH | 7.6 | 7.6 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94168 |
WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94124 |
WordPress WP EasyCart plugin <= 5.9.4 - SQL Injection vulnerability | HIGH | 8.5 | 8.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94118 |
WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94080 |
WordPress MarketKing plugin <= 2.1.70 - Broken Access Control vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-94079 |
WordPress WP User Manager plugin <= 2.9.19 - Broken Access Control vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93774 |
WordPress WP Photo Album Plus plugin <= 9.3.02.002 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93773 |
WordPress Mollie Forms plugin <= 2.11.0 - SQL Injection vulnerability | HIGH | 8.5 | 8.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93772 |
WordPress wpForo Forum plugin <= 3.1.5 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93623 |
WordPress AI Engine plugin <= 3.7.8 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 5.3 | 5.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93622 |
WordPress WPS Limit Login plugin <= 1.5.9.3 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93620 |
WordPress PayPlus Payment Gateway plugin <= 8.2.5 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93618 |
WordPress JetTricks plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93529 |
WordPress WSP MCP - AI Agents Connector plugin <= 2.7.0 - Broken Access Control vulnerability | MEDIUM | 6.5 | 6.5 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-93527 |
WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability | HIGH | 8.5 | 8.5 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93526 |
WordPress Event Tickets plugin <= 5.29.4 - Cross Site Scripting (XSS) vulnerability | HIGH | 7.1 | 7.1 | — | Patchstack | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93513 |
WordPress SiteSkite plugin <= 2.1.7 - Insecure Direct Object References (IDOR) vulnerability | MEDIUM | 4.3 | 4.3 | — | Patchstack | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77420 |
JLine: ReDoS via `HISTORY_IGNORE` Configuration Variable | MEDIUM | 5.5 | 5.5 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77422 |
JLine: ReDoS in Built-in grep Command Amplified by Automatic `.*` Wrapping | HIGH | 7.5 | 7.5 | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-75131 |
NetworkManager-l2tp Privilege Escalation via pppd Username Injection | HIGH | 8.5 | 7.8 | — | VulnCheck | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-96541 |
Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline | HIGH | 7.5 | 7.5 | — | redhat | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-71459 |
Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary … | MEDIUM | 5.0 | 5.0 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-71458 |
Automation-controller: automation-controller-container: automation-controller: named-url 404 body oracle enables cross-t… | MEDIUM | 5.0 | 5.0 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77421 |
JLine: ReDoS in Nano Editor Regex Search Mode | MEDIUM | 6.5 | 6.5 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92730 |
LimeSurvey Community Edition 7.0.14 - Reflected XSS in participant CSV import result via invalid attribute column name | HIGH | 7.4 | — | — | Fluid Attacks | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-63132 |
OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack | CRITICAL | 9.2 | — | — | GitHub_M | 2026-09-23 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-63131 |
OpenBao LIST ACL bypass: a trailing-slash LIST request skips a more-specific deny rule (unported Vault v2.0.3 fix) | MEDIUM | 6.0 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-77285 |
OpenBao Agent Writes Secrets to Stdout | LOW | 2.4 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-55632 |
GoCD is vulnerable to authorization bypass via pipeline structure API | MEDIUM | 4.3 | 4.3 | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-52744 |
GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API | MEDIUM | 5.3 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92700 |
Caddy: fileHidden() case-sensitive pattern bypass — exposes "hidden" files via case variation | MEDIUM | 6.3 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-92284 |
Caddy: Unbounded body buffer via {http.request.body} placeholder — memory exhaustion DoS | MEDIUM | 6.9 | — | — | GitHub_M | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88840 |
Busybox: busybox: tls ssl_server reads one byte out of bounds when parsing truncated clienthello | MEDIUM | 5.3 | 5.3 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |
CVE-2026-88839 |
Busybox: busybox: passwd/group parser writes heap pointers out of bounds due to stale tokenize() endpoint | MEDIUM | 6.7 | 6.7 | — | redhat | 2026-09-23 | 10 | — | raw · ⬇ |