Search
Search Results (43609 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96828 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. | ||||
| CVE-2026-96827 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | ||||
| CVE-2026-96823 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. | ||||
| CVE-2026-96822 | 2026-09-30 | 9.3 Critical | ||
| Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. | ||||
| CVE-2026-96818 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions. | ||||
| CVE-2026-96817 | 2026-09-30 | 8.2 High | ||
| Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions. | ||||
| CVE-2026-96348 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Bookly <= 28.2 versions. | ||||
| CVE-2026-96346 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in WP ERP <= 1.17.9 versions. | ||||
| CVE-2026-96345 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in Estatik <= 4.3.5 versions. | ||||
| CVE-2026-95587 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions. | ||||
| CVE-2026-94499 | 2026-09-30 | 7.1 High | ||
| Subscriber Broken Access Control in FormGent <= 1.12.2 versions. | ||||
| CVE-2026-94177 | 2026-09-30 | 8.5 High | ||
| Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions. | ||||
| CVE-2026-94120 | 2026-09-30 | 7.5 High | ||
| Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions. | ||||
| CVE-2026-94115 | 2026-09-30 | 8.5 High | ||
| Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions. | ||||
| CVE-2026-94082 | 2026-09-30 | 7.6 High | ||
| Author SQL Injection in Quiz Cat <= 3.1.1 versions. | ||||
| CVE-2026-94074 | 2026-09-30 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions. | ||||
| CVE-2026-93621 | 2026-09-30 | 8.2 High | ||
| Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | ||||
| CVE-2026-62085 | 2026-09-30 | 7.6 High | ||
| Administrator SQL Injection in WP Activity Log <= 5.6.6 versions. | ||||
| CVE-2026-27085 | 2026-09-30 | 2.7 Low | ||
| Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. | ||||
| CVE-2026-103117 | 1 Os4ed | 1 Opensis-classic | 2026-09-30 | 4.7 Medium |
| A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save Data Handler. Such manipulation of the argument values leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet. | ||||