CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 499 of 500
CVE-2026-12741
HIGH

The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[s]' parameter in all versions up to, and inclu...

CVSS 7.5 2026-07-28
CVE-2026-16585
HIGH

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation...

CVSS 7.2 2026-07-28
CVE-2026-14924
HIGH

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to c...

CVSS 7.5 2026-07-28
CVE-2026-14870
HIGH

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page...

CVSS 7.1 2026-07-28
CVE-2026-14490
HIGH

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vul...

CVSS 7.5 2026-07-28
CVE-2026-17524
HIGH

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypa...

CVSS 7.5 2026-07-28
CVE-2026-66473
HIGH

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

CVSS 7.5 2026-07-27
CVE-2026-65447
HIGH

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.

CVSS 7.1 2026-07-27
CVE-2026-65446
HIGH

Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.

CVSS 7.1 2026-07-27
CVE-2026-65443
HIGH

Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions.

CVSS 7.1 2026-07-27
CVE-2026-65442
HIGH

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

CVSS 7.2 2026-07-27
CVE-2026-65441
HIGH

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions.

CVSS 7.1 2026-07-27
CVE-2026-65440
HIGH

Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.

CVSS 7.1 2026-07-27
CVE-2026-65439
HIGH

Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.

CVSS 7.1 2026-07-27
CVE-2026-65438
HIGH

Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.

CVSS 7.1 2026-07-27
CVE-2026-65437
HIGH

Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions.

CVSS 7.1 2026-07-27
CVE-2026-61957
HIGH

Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.

CVSS 7.1 2026-07-27
CVE-2026-61953
HIGH

Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.

CVSS 7.2 2026-07-27
CVE-2025-63913
HIGH

An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' fun...

CVSS 7.5 2026-07-27
CVE-2026-55685
HIGH

React Router is a router for React. In versions 7.0.0 through 7.17.0, the manifest endpoint could be accessed via unauthenticated targeted requests that would put heavy load on the...

CVSS 7.5 Shopify react-router 2026-07-27
1 497 498 499 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.