CVEs
Common Vulnerabilities & Exposures ingested from CVE Project cvelistV5, NVD and EUVD. Filter by year or search by ID / title.
229687 CVEs matched. Showing 2201–2250 (page 45 of 4594).
HIGH and CRITICAL CVEs are auto-promoted to the Threats table; the Threat column below shows the link when a promotion exists.
Click a column header to sort all results; click the active column again to reverse.
| CVE-ID ↕ | Title ↕ | Severity ↕ | Score (overview) ↕ | NVD Score | MSRC Score | CNA ↕ | Published ↕ | Remediations | Threat | Source |
|---|---|---|---|---|---|---|---|---|---|---|
CVE-2026-89422 |
TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension | CRITICAL | 9.3 | — | — | EEF | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93928 |
WordPress Taxi Booking Manager for WooCommerce plugin < 2.0.8 - Broken Authentication vulnerability | HIGH | 7.3 | 7.3 | — | Patchstack | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95508 |
Libslirp: libslirp: heap buffer overflow in dhcpv6/tftp response builders on small interface mtu | HIGH | 7.4 | 7.4 | 7.0 | redhat | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-95511 |
CVE-2026-95511 | — | — | — | — | redhat | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-15095 |
Product Feed Manager for WooCommerce <= 6.6.43 - Authenticated (Shop Manager+) Path Traversal to File Deletion via 'prov… | MEDIUM | 4.9 | 4.9 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-9231 |
WP Travel Engine <= 6.8.0 - Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute | HIGH | 7.5 | 7.5 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-95503 |
Keycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabled | MEDIUM | 6.8 | 6.8 | — | redhat | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93836 |
WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter | HIGH | 7.2 | 7.2 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-9004 |
WP-CRM System <= 3.4.6 - Authenticated (Contributor+) Exposure of Sensitive Information via 'contact_id' Parameter | MEDIUM | 4.3 | 4.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-7622 |
ThumbPress <= 6.2.1 - Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation | MEDIUM | 4.3 | 4.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-18345 |
WP User Manager <= 2.9.18 - Missing Authorization to Authenticated (Subscriber+) Stripe Account Hijack via Stripe Connec… | MEDIUM | 4.3 | 4.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2025-1280 |
BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Read | MEDIUM | 6.5 | 6.5 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2025-14487 |
Handily <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Stripe Payment Settings Modification via 'stripe_p… | MEDIUM | 5.3 | 5.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93778 |
WP Yelp Review Slider <= 9.2 - Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_dow… | HIGH | 7.2 | 7.2 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-92235 |
WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_re… | HIGH | 8.1 | 8.1 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-91092 |
wpForo Forum <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Ac… | MEDIUM | 4.3 | 4.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-6922 |
WP Table Builder <= 2.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Par… | HIGH | 7.1 | 7.1 | — | Wordfence | 2026-09-22 | 2 | ⚠ Threat | raw · ⬇ |
CVE-2026-1645 |
Hostel <= 1.1.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_currency' Parameter and Localiz… | MEDIUM | 4.4 | 4.4 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-18439 |
Tutor LMS <= 4.0.7 - Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modifica… | MEDIUM | 4.3 | 4.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2025-1281 |
BM Content Builder < 3.17.1 - Authenticated (Subscriber+) Arbitrary File Deletion | HIGH | 8.8 | 8.8 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-4123 |
RW Elephant Rental Inventory <= 2.3.13 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via… | MEDIUM | 4.3 | 4.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2025-14484 |
Image Buzz <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary API Key Modification via 'pixabay_api' Paramete… | MEDIUM | 5.3 | 5.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2025-14486 |
PixelPlay <= 1.0.2 - Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter | MEDIUM | 5.3 | 5.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-92969 |
HUSKY <= 1.4.4 - Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX | HIGH | 8.1 | 8.1 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-16778 |
Live Composer <= 2.1.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Sh… | MEDIUM | 6.4 | 6.4 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-12995 |
Custom Field Template <= 2.7.8 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File D… | MEDIUM | 4.3 | 4.3 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93952 |
Security Advisory 0183 | CRITICAL | 9.5 | 10.0 | — | Arista | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-87082 |
Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in… | — | — | 7.5 | — | CPANSec | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-87081 |
Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label… | — | — | 7.5 | — | CPANSec | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-87080 |
Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never… | — | — | 9.1 | — | CPANSec | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-87079 |
Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long… | — | — | 7.5 | — | CPANSec | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-87078 |
Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_pu… | — | — | 9.1 | — | CPANSec | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-74766 |
Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that r… | — | — | 8.4 | — | CPANSec | 2026-09-22 | 20 | ⚠ Threat | raw · ⬇ |
CVE-2026-74765 |
Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumula… | — | — | 6.5 | — | CPANSec | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-91827 |
Ninja Forms 3.15.3 - Unauthenticated PHP Object Injection via CSV Export | HIGH | 7.5 | 7.5 | — | WPScan | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-92438 |
Ninja Forms 3.15.3 - Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin | HIGH | 8.8 | 8.8 | — | WPScan | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-94504 |
Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting | HIGH | 7.2 | 7.2 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-89412 |
TranslatePress <= 3.3.5 - Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel | HIGH | 7.2 | 7.2 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-88788 |
Text Styler <= 1.1.1 - Contributor+ Stored XSS | — | — | 6.8 | — | WPScan | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93655 |
Booking Calendar <= 11.8.3 - Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter | MEDIUM | 6.1 | 6.1 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-12470 |
CMP <= 4.1.17 - Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJA… | HIGH | 7.2 | 7.2 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-85653 |
Contextual Related Posts <= 4.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Par… | MEDIUM | 6.4 | 6.4 | — | Wordfence | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-19658 |
Give Tributes <= 2.3.1 - Unauthenticated PHP Object Injection via 'give_tributes_ecard_notify[recipient][personalized][]… | CRITICAL | 9.8 | 9.8 | — | Wordfence | 2026-09-22 | 1 | ⚠ Threat | raw · ⬇ |
CVE-2026-13355 |
Meta Box AIO <= 3.11.0 And Standalone Plugin Extensions - Unauthenticated Privilege Escalation to Administrator to 'rwmb… | CRITICAL | 9.8 | 9.8 | — | Wordfence | 2026-09-22 | 3 | ⚠ Threat | raw · ⬇ |
CVE-2026-94493 |
Gigatech PDV5701 WebSocket Service index.html missing authentication | CRITICAL | 10.0 | 10.0 | — | VulDB | 2026-09-22 | 10 | ⚠ Threat | raw · ⬇ |
CVE-2026-93712 |
Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the … | — | — | — | — | CPANSec | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93711 |
Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array | — | — | — | — | CPANSec | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93710 |
Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler … | — | — | — | — | CPANSec | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-93709 |
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard… | — | — | — | — | CPANSec | 2026-09-22 | 10 | — | raw · ⬇ |
CVE-2026-94492 |
Yonyou U8cloud OpenAPI so.saleorder.sendaudit sql injection | MEDIUM | 5.3 | 6.3 | — | VulDB | 2026-09-22 | 10 | — | raw · ⬇ |