Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26395
Total
1955
Critical
7973
High
8225
Medium
CVE ID Severity Score Description Published
CVE-2026-42775 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions. Jun 15, 2026
CVE-2026-42752 MEDIUM 6.5 Unauthenticated Bypass Vulnerability in Stripe Payments <= 2.0.98 versions. Jun 15, 2026
CVE-2026-42743 MEDIUM 6.5 Unauthenticated Broken Authentication in Masteriyo - LMS <= 2.1.8 versions. Jun 15, 2026
CVE-2026-42688 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Modula Image Gallery <= 2.14.23 versions. Jun 15, 2026
CVE-2026-42687 HIGH 8.1 Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions. Jun 15, 2026
CVE-2026-42686 HIGH 7.1 Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions. Jun 15, 2026
CVE-2026-42668 HIGH 7.5 Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. Jun 15, 2026
CVE-2026-42667 HIGH 7.5 Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions. Jun 15, 2026
CVE-2026-42666 HIGH 7.5 Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions. Jun 15, 2026
CVE-2026-42665 CRITICAL 9.3 Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions. Jun 15, 2026
CVE-2026-42664 HIGH 8.2 Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search <= 1.38.2 versions. Jun 15, 2026
CVE-2026-42663 MEDIUM 6.5 Unauthenticated Cross Site Scripting (XSS) in Simple Membership <= 4.7.2 versions. Jun 15, 2026
CVE-2026-42662 MEDIUM 6.5 Unauthenticated Bypass Vulnerability in Event Tickets <= 5.27.5 versions. Jun 15, 2026
CVE-2026-42661 HIGH 8.8 Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. Jun 15, 2026
CVE-2026-42660 MEDIUM 6.5 Subscriber Sensitive Data Exposure in Contest Gallery <= 28.1.7 versions. Jun 15, 2026
CVE-2026-42659 MEDIUM 6.5 Subscriber Broken Access Control in Advanced Form Integration <= 1.126.12 versions. Jun 15, 2026
CVE-2026-42658 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions. Jun 15, 2026
CVE-2026-42657 MEDIUM 5.3 Unauthenticated Other Vulnerability Type in Contest Gallery <= 28.1.7 versions. Jun 15, 2026
CVE-2026-42656 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions. Jun 15, 2026
CVE-2026-42655 MEDIUM 5.9 Unauthenticated Bypass Vulnerability in Best Payments Plugin for WP <= 4.6.19 versions. Jun 15, 2026
CVE-2026-42651 MEDIUM 6.3 Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions. Jun 15, 2026
CVE-2026-42650 HIGH 7.2 Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions. Jun 15, 2026
CVE-2026-42649 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions. Jun 15, 2026
CVE-2026-42640 MEDIUM 6.5 Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. Jun 15, 2026
CVE-2026-42639 CRITICAL 9.3 Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions. Jun 15, 2026