s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVEs

Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.

Reset

229687 CVEs matched. Showing 2201–2250 (page 45 of 4594).

HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.

Click a column header to sort all results; click the active column again to reverse.

CVE-ID ↕ Title ↕ Severity ↕ Score (overview) ↕ NVD Score MSRC Score CNA ↕ Published ↕ Remediations Threat Source
CVE-2026-89422 TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension CRITICAL 9.3 — — EEF 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93928 WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vulnerability HIGH 7.3 7.3 — Patchstack 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95508 Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu HIGH 7.4 7.4 7.0 redhat 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-95511 CVE-2026-95511 — — — — redhat 2026-09-22 10 — raw · ⬇
CVE-2026-15095 Product Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Traversal to File Deletion via 'prov… MEDIUM 4.9 4.9 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-9231 WP Travel Engine <= 6.8.0 - Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute HIGH 7.5 7.5 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-95503 Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabled MEDIUM 6.8 6.8 — redhat 2026-09-22 10 — raw · ⬇
CVE-2026-93836 WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter HIGH 7.2 7.2 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-9004 WP-CRM System <= 3.4.6 - Authenticated (Contributor+) Exposure of Sensitive Information via 'contact_id' Parameter MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-7622 ThumbPress <= 6.2.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-18345 WP User Manager <= 2.9.18 - Missing Authorization to Authenticated (Subscriber+) Stripe Account Hijack via Stripe Connec… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-1280 BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Read MEDIUM 6.5 6.5 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-14487 Handily <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Stripe Payment Settings Modification via 'stripe_p… MEDIUM 5.3 5.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-93778 WP Yelp Review Slider <= 9.2 - Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_dow… HIGH 7.2 7.2 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-92235 WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_re… HIGH 8.1 8.1 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-91092 wpForo Forum <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Ac… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-6922 WP Table Builder <= 2.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Par… HIGH 7.1 7.1 — Wordfence 2026-09-22 2 ⚠ Threat raw · ⬇
CVE-2026-1645 Hostel <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_currency' Parameter and Localiz… MEDIUM 4.4 4.4 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-18439 Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modifica… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-1281 BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Deletion HIGH 8.8 8.8 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-4123 RW Elephant Rental Inventory <= 2.3.13 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-14484 Image Buzz <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary API Key Modification via 'pixabay_api' Paramete… MEDIUM 5.3 5.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2025-14486 PixelPlay <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter MEDIUM 5.3 5.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-92969 HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX HIGH 8.1 8.1 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-16778 Live Composer <= 2.1.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Sh… MEDIUM 6.4 6.4 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-12995 Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File D… MEDIUM 4.3 4.3 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-93952 Security Advisory 0183 CRITICAL 9.5 10.0 — Arista 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-87082 Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in… — — 7.5 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-87081 Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label… — — 7.5 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-87080 Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never… — — 9.1 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-87079 Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long… — — 7.5 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-87078 Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_pu… — — 9.1 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-74766 Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that r… — — 8.4 — CPANSec 2026-09-22 20 ⚠ Threat raw · ⬇
CVE-2026-74765 Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumula… — — 6.5 — CPANSec 2026-09-22 10 — raw · ⬇
CVE-2026-91827 Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export HIGH 7.5 7.5 — WPScan 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-92438 Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin HIGH 8.8 8.8 — WPScan 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-94504 Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting HIGH 7.2 7.2 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-89412 TranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel HIGH 7.2 7.2 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-88788 Text Styler <= 1.1.1 - Contributor+ Stored XSS — — 6.8 — WPScan 2026-09-22 10 — raw · ⬇
CVE-2026-93655 Booking Calendar <= 11.8.3 - Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter MEDIUM 6.1 6.1 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-12470 CMP <= 4.1.17 - Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJA… HIGH 7.2 7.2 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-85653 Contextual Related Posts <= 4.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Par… MEDIUM 6.4 6.4 — Wordfence 2026-09-22 10 — raw · ⬇
CVE-2026-19658 Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]… CRITICAL 9.8 9.8 — Wordfence 2026-09-22 1 ⚠ Threat raw · ⬇
CVE-2026-13355 Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb… CRITICAL 9.8 9.8 — Wordfence 2026-09-22 3 ⚠ Threat raw · ⬇
CVE-2026-94493 Gigatech PDV5701 WebSocket Service index.html missing authentication CRITICAL 10.0 10.0 — VulDB 2026-09-22 10 ⚠ Threat raw · ⬇
CVE-2026-93712 Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the … — — — — CPANSec 2026-09-22 10 — raw · ⬇
CVE-2026-93711 Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array — — — — CPANSec 2026-09-22 10 — raw · ⬇
CVE-2026-93710 Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler … — — — — CPANSec 2026-09-22 10 — raw · ⬇
CVE-2026-93709 Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard… — — — — CPANSec 2026-09-22 10 — raw · ⬇
CVE-2026-94492 Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection MEDIUM 5.3 6.3 — VulDB 2026-09-22 10 — raw · ⬇