Export limit exceeded: 40827 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40827 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-22335 | 2 Wc Lovers., Wordpress | 2 Woocommerce Frontend Manager – Ultimate, Wordpress | 2026-06-20 | 8.5 High |
| Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions. | ||||
| CVE-2026-22340 | 2 Jobster Marketplace, Wordpress | 2 Wpjobster, Wordpress | 2026-06-20 | 9.3 Critical |
| Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. | ||||
| CVE-2026-22343 | 2 Premiumpress Limited., Wordpress | 2 Wordpress Dating Theme, Wordpress | 2026-06-20 | 8.6 High |
| Unauthenticated Broken Access Control in WordPress Dating Theme <= 11.2.0 versions. | ||||
| CVE-2026-40726 | 2 Themegrill, Wordpress | 2 User Registration Stripe, Wordpress | 2026-06-20 | 8.2 High |
| Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.14 versions. | ||||
| CVE-2026-48875 | 2 Jetimpex Inc., Wordpress | 2 Jetsmartfilters, Wordpress | 2026-06-20 | 9.3 Critical |
| Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. | ||||
| CVE-2026-49072 | 2 Opmc, Wordpress | 2 Woocommerce Anti-fraud, Wordpress | 2026-06-20 | 6.5 Medium |
| Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions. | ||||
| CVE-2026-49076 | 2 Jetimpex Inc., Wordpress | 2 Jetengine, Wordpress | 2026-06-20 | 9.3 Critical |
| Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. | ||||
| CVE-2026-49079 | 2 Jetimpex Inc., Wordpress | 2 Jetsearch, Wordpress | 2026-06-20 | 9.3 Critical |
| Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. | ||||
| CVE-2026-49081 | 2 Themegrill, Wordpress | 2 User Registration Stripe, Wordpress | 2026-06-20 | 8.2 High |
| Unauthenticated Broken Access Control in User Registration Stripe <= 1.3.12 versions. | ||||
| CVE-2026-49084 | 2 Jetimpex Inc., Wordpress | 2 Jetengine, Wordpress | 2026-06-20 | 9.3 Critical |
| Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. | ||||
| CVE-2026-54185 | 2 Themeco, Wordpress | 2 Cornerstone, Wordpress | 2026-06-20 | 8.5 High |
| Subscriber SQL Injection in Cornerstone < 7.8.8 versions. | ||||
| CVE-2026-54187 | 2 Jetimpex Inc., Wordpress | 2 Jetengine, Wordpress | 2026-06-20 | 9.3 Critical |
| Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | ||||
| CVE-2026-54803 | 2 Cozyvision, Wordpress | 2 Sms Alert Order Notifications, Wordpress | 2026-06-20 | 9.8 Critical |
| Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. | ||||
| CVE-2024-33685 | 2 Jegstudio, Wordpress | 2 Startupzy, Wordpress | 2026-06-20 | 4.3 Medium |
| Missing Authorization vulnerability in Jegstudio Startupzy startupzy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Startupzy: from n/a through 1.1.1. | ||||
| CVE-2024-31435 | 2 Inisev, Wordpress | 2 Social Media & Share Icons, Wordpress | 2026-06-20 | 4.3 Medium |
| : Missing Authorization vulnerability in Inisev Social Media & Share Icons allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Social Media & Share Icons: from n/a through 2.8.6. | ||||
| CVE-2026-11858 | 1 Quanos Solutions | 1 Schema St4 | 2026-06-20 | N/A |
| Quanos SCHEMA ST4 on-premises contains a local privilege escalation vulnerability in the Client Update Service. The update service runs as NT AUTHORITY\SYSTEM and exposes a .NET Remoting interface over a named pipe without sufficient access controls or authorization. A local authenticated low-privileged user can connect to the interface and invoke privileged update methods such as Update(). This allows arbitrary file write and delete operations with SYSTEM privileges and can be used to achieve local privilege escalation. | ||||
| CVE-2024-37210 | 2 Ali2woo, Wordpress | 2 Alinext, Wordpress | 2026-06-20 | 6.5 Medium |
| Missing Authorization vulnerability in ali2woo AliNext allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects AliNext: from n/a through 3.3.5. | ||||
| CVE-2024-37496 | 2 Rara Themes, Wordpress | 2 Metro Magazine, Wordpress | 2026-06-20 | 4.3 Medium |
| Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Metro Magazine: from n/a through 1.3.7. | ||||
| CVE-2025-59554 | 2 Advanced Ads Gmbh, Wordpress | 2 Advanced Ads – Tracking, Wordpress | 2026-06-20 | 9.3 Critical |
| Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | ||||
| CVE-2026-54819 | 2 Webilia Inc., Wordpress | 2 Listdom, Wordpress | 2026-06-20 | 9.3 Critical |
| Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0. | ||||