Busca de CVEs

375.173 resultados
CVE-2026-12136MEDIUMSysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode AttributesEPSS 0.2%CVE-2026-55746HIGHCotonti stored XSS via PFS folder titleEPSS 0.2%CVE-2026-28573CRITICALIn AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial EPSS 0.1%CVE-2026-55745MEDIUMCotonti CSRF in PFS folder edit allows unauthorized folder modificationEPSS 0.1%CVE-2026-55744HIGHCotonti CSRF in PFS allows forced arbitrary file uploadEPSS 0.2%CVE-2026-55742CRITICALCotonti CSRF in admin.rights.php allows privilege escalationEPSS 0.2%CVE-2026-55741HIGHCotonti CSRF in admin.config.php allows unauthorized configuration changesEPSS 0.2%CVE-2026-9815MEDIUMMagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCEEPSS 0.2%CVE-2026-55740CRITICALSQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameterEPSS 0.4%CVE-2026-11358MEDIUMOrbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' ParameterEPSS 0.3%CVE-2026-11402MEDIUMServices Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block AttributeEPSS 0.2%CVE-2026-11784MEDIUMOptimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX ActionEPSS 0.2%CVE-2026-12093MEDIUMSimple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' WebhookEPSS 0.4%CVE-2026-10736MEDIUMTutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' ParameterEPSS 0.5%CVE-2026-10623MEDIUMPressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification via 'quiz_id', 'item_id', and 'rule_id' ParametersEPSS 0.3%CVE-2026-11360MEDIUMAdvanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injection via 'sort_direction' ParameterEPSS 0.5%CVE-2026-11357MEDIUMKadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData LocalizationEPSS 0.3%CVE-2026-11776MEDIUMForm Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' ParameterEPSS 0.3%CVE-2026-10029MEDIUMEvent Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API EndpointsEPSS 0.3%CVE-2026-9860HIGHOffload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX ActionEPSS 0.6%