CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Last 7 days
3,657 result(s) · page 183 of 183
CVE-2026-81429
HIGH

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise the imported data befo...

CVSS 7.1 2026-09-12
CVE-2026-81402
CRITICAL

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing unauthentica...

CVSS 9.8 2026-09-12
CVE-2026-81090
HIGH

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a log...

CVSS 7.2 2026-09-12
CVE-2026-80494
HIGH

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public endpoint that lacks any authoriza...

CVSS 8.6 2026-09-12
CVE-2026-80491
HIGH

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthent...

CVSS 8.6 2026-09-12
CVE-2026-78152
MEDIUM

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing...

CVSS 5.3 2026-09-12
CVE-2026-77753
MEDIUM

The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one when the tempora...

CVSS 5.5 2026-09-12
CVE-2026-77752
HIGH

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before granting the n...

CVSS 7.2 2026-09-12
CVE-2026-77705
HIGH

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled to modify the WordP...

CVSS 7.2 2026-09-12
CVE-2026-77689
MEDIUM

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as paid, trusting the p...

CVSS 5.3 2026-09-12
CVE-2026-77006
CRITICAL

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the resu...

CVSS 9.6 2026-09-12
CVE-2026-77005
CRITICAL

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making ...

CVSS 9.6 2026-09-12
CVE-2026-75800
CRITICAL

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticate...

CVSS 9.8 2026-09-12
CVE-2026-87719
CRITICAL

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an ...

CVSS 9.9 2026-09-12
CVE-2026-85706
KEV CRITICAL

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthe...

CVSS 10 Gitlab gitlab 2026-09-12
CVE-2026-89268
MEDIUM

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authe...

CVSS 5.4 2026-09-12
CVE-2026-89266
HIGH

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a m...

CVSS 8.2 2026-09-12
1 181 182 183
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.