Vulnerabilities (CVE)

Total 398697 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-28148 2026-08-14 N/A 9.8 CRITICAL
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
CVE-2026-66436 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
CVE-2026-28001 2026-08-14 N/A 9.3 CRITICAL
Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.
CVE-2026-27345 2026-08-14 N/A 7.5 HIGH
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
CVE-2026-28155 2026-08-14 N/A 6.5 MEDIUM
Unauthenticated Insecure Direct Object References (IDOR) in Do Lasso <= 358 versions.
CVE-2026-28156 2026-08-14 N/A 8.5 HIGH
Subscriber SQL Injection in Do Lasso <= 358 versions.
CVE-2026-61978 2026-08-14 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in Secure Card Gateway for ePay Paycenter (Piraeus Bank) <= 1.0.32 versions.
CVE-2026-28154 2026-08-14 N/A 7.1 HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in snstheme Samex - Clean, Minimal Shop WooCommerce WordPress Theme and snstheme M.Anh - Fashion WooCoommerce WordPress Theme allows Reflected XSS. This issue affects Samex - Clean, Minimal Shop WooCommerce WordPress Theme: from n/a through 2.5; M.Anh - Fashion WooCoommerce WordPress Theme: from n/a through 1.7.
CVE-2026-66429 2026-08-14 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.10 versions.
CVE-2026-27539 2026-08-14 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
CVE-2026-66441 2026-08-14 N/A 7.5 HIGH
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
CVE-2026-66462 2026-08-14 N/A 7.5 HIGH
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
CVE-2026-61966 2026-08-14 N/A 9.3 CRITICAL
Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
CVE-2026-28159 2026-08-14 N/A 6.5 MEDIUM
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
CVE-2026-28004 2026-08-14 N/A 7.1 HIGH
Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
CVE-2026-27999 2026-08-14 N/A 6.5 MEDIUM
Subscriber Broken Access Control in Tourfic <= 2.23.1 versions.
CVE-2026-66432 2026-08-14 N/A 7.5 HIGH
Subscriber Sensitive Data Exposure in WPJAM Basic <= 7.0.2.1 versions.
CVE-2026-28174 2026-08-14 N/A 6.5 MEDIUM
Customer Sensitive Data Exposure in WP Event SOlution <= 4.1.18 versions.
CVE-2026-66459 2026-08-14 N/A 6.5 MEDIUM
Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions.
CVE-2026-28002 2026-08-14 N/A 8.5 HIGH
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arraytics Booktics allows Blind SQL Injection. This issue affects Booktics: from n/a through 1.0.22.