CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Medium
10,000 result(s) · page 486 of 500
CVE-2026-9612
MEDIUM

The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the yapacdev_...

CVSS 5.3 2026-06-24
CVE-2026-9175
MEDIUM

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This is due ...

CVSS 5.3 2026-06-24
CVE-2026-9172
MEDIUM

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability check on...

CVSS 5.3 2026-06-24
CVE-2026-8905
MEDIUM

The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect nonce va...

CVSS 6.1 2026-06-24
CVE-2026-8896
MEDIUM

The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_text') of t...

CVSS 6.4 2026-06-24
CVE-2026-8865
MEDIUM

The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and including,...

CVSS 6.4 2026-06-24
CVE-2026-8690
MEDIUM

The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin no...

CVSS 5.3 2026-06-24
CVE-2026-8628
MEDIUM

The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficient input ...

CVSS 6.1 2026-06-24
CVE-2026-8622
MEDIUM

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to insuffi...

CVSS 6.1 2026-06-24
CVE-2026-8617
MEDIUM

The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capability che...

CVSS 5.3 2026-06-24
CVE-2026-7617
MEDIUM

The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not properly verifying that a use...

CVSS 5.3 2026-06-24
CVE-2026-12094
MEDIUM

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the cf7cdb_ajax_delete_user() func...

CVSS 5.3 2026-06-24
CVE-2026-11370
MEDIUM

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible ...

CVSS 6.4 2026-06-24
CVE-2026-10531
MEDIUM

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contr...

CVSS 5.4 2026-06-24
CVE-2026-9539
MEDIUM

An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g....

CVSS 6.5 2026-06-24
CVE-2026-12488
MEDIUM

A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially crafted network request can lead to a denial of service. An at...

CVSS 6.2 2026-06-24
CVE-2026-11614
MEDIUM

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, and incl...

CVSS 6.4 2026-06-24
CVE-2026-6458
MEDIUM

Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with emp...

CVSS 5.1 2026-06-24
CVE-2026-48493
MEDIUM

Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant themselves any...

CVSS 5.5 Snipeitapp snipe-it 2026-06-23
CVE-2026-47693
MEDIUM

Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its log export funct...

CVSS 6.9 2026-06-23
1 484 485 486 487 488 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.