Busca de CVEs

390.674 resultados
CVE-2026-9833HIGHTag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' ParameterEPSS 0.3%CVE-2026-8825MEDIUMElementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST APIEPSS 0.4%CVE-2026-13432MEDIUMThumbPress < 6.2.2 - Subscriber+ Plugin DeactivationEPSS 0.3%CVE-2026-13156MEDIUMMailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRFEPSS 0.1%CVE-2026-13147CRITICALKirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apisEPSS 0.9%CVE-2026-13142HIGHPasswordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute ForceEPSS 0.4%CVE-2026-12973MEDIUMPayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status ModificationEPSS 0.3%CVE-2026-12972MEDIUMPayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata TamperingEPSS 0.3%CVE-2026-12970HIGHLearnPress < 4.4.1 - Reflected XSS via c_searchEPSS 0.3%CVE-2026-12898MEDIUMAll-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path TraversalEPSS 1.4%CVE-2026-12724MEDIUMKirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-passwordEPSS 0.1%CVE-2026-12723MEDIUMKirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component LibraryEPSS 0.3%CVE-2026-12592HIGHSlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry HeaderEPSS 0.4%CVE-2026-11868MEDIUMWP Travel < 11.7.1 - Unauthenticated Arbitrary Booking CancellationEPSS 0.3%CVE-2026-11349HIGHModern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_moreEPSS 0.4%CVE-2026-10755LOWAll in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI IntegrationEPSS 0.3%CVE-2026-10724MEDIUMReviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google ReviewsEPSS 0.1%CVE-2026-10081HIGHUnlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews WidgetEPSS 0.3%CVE-2026-26081MEDIUMHAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also EPSS 0.5%CVE-2026-26080LOWHAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALEPSS 0.5%