Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,225
Critical1,270
High4,356
Medium12,382
Reset
Showing 1981-2000 of 18225 records
Threat Entry Updated 2026-07-24

CVE-2026-24638 - RepairBuddy Plugin

Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121.

PLUGIN RepairBuddy

CVE-2026-24638

MEDIUM CVSS 4.3 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-39655 - Mayosis Core Plugin

Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Mayosis Core: from n/a through 5.4.7.

PLUGIN Mayosis Core

CVE-2026-39655

MEDIUM CVSS 5.3 2026-05-26
Threat Entry Updated 2026-07-24

CVE-2026-42774 - JetEngine Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.

PLUGIN JetEngine

CVE-2026-42774

CRITICAL CVSS 9.3 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-45216 - Smart Manager Plugin

Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects Smart Manager: from n/a through 8.85.0.

PLUGIN Smart Manager

CVE-2026-45216

HIGH CVSS 8.8 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-48837 - Elementor Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8.

PLUGIN Elementor

CVE-2026-48837

HIGH CVSS 8.5 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-45438 - Smart Coupons for WooCommerce Plugin

Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Smart Coupons for WooCommerce: from n/a before 2.3.0.

PLUGIN Smart Coupons for WooCommerce

CVE-2026-45438

HIGH CVSS 7.5 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-45209 - MyCryptoCheckout Plugin

Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MyCryptoCheckout: from n/a through 2.161.

PLUGIN MyCryptoCheckout

CVE-2026-45209

HIGH CVSS 7.5 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-45435 - WP Activity Log Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.

PLUGIN WP Activity Log

CVE-2026-45435

MEDIUM CVSS 6.5 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-45217 - Stripe Payment Gateway for WooCommerce Plugin

Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation. This issue affects Stripe Payment Gateway for WooCommerce: from n/a through 5.0.7.

PLUGIN Stripe Payment Gateway for WooCommerce

CVE-2026-45217

MEDIUM CVSS 6.5 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-42776 - Sunshine Photo Cart Plugin

Missing Authorization vulnerability in WP Sunshine Sunshine Photo Cart allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sunshine Photo Cart: from n/a through 3.6.7.

PLUGIN Sunshine Photo Cart

CVE-2026-42776

MEDIUM CVSS 6.3 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-42773 - eMagicOne Store Manager Plugin

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eMagicOne eMagicOne Store Manager allows Blind SQL Injection. This issue affects eMagicOne Store Manager: from n/a through 1.3.2.

PLUGIN eMagicOne Store Manager

CVE-2026-42773

CRITICAL CVSS 9.3 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-24937 - Broadcast Live Video Plugin

Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows Code Injection. This issue affects Broadcast Live Video: from n/a before 7.1.3.

PLUGIN Broadcast Live Video

CVE-2026-24937

HIGH CVSS 7.2 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-39436 - CformsII Plugin

Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affects CformsII: from n/a through 15.1.3.

PLUGIN CformsII

CVE-2026-39436

HIGH CVSS 7.1 2026-05-25
Threat Entry Updated 2026-07-20

CVE-2026-42763 - SePay Gateway Plugin

Missing Authorization vulnerability in SePay team SePay Gateway allows Retrieve Embedded Sensitive Data. This issue affects SePay Gateway: from n/a through 1.1.20.

PLUGIN SePay Gateway

CVE-2026-42763

MEDIUM CVSS 6.5 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-32389 - NanoCare Plugin

Missing Authorization vulnerability in Linethemes NanoCare allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects NanoCare: from n/a before 1.2.2.

PLUGIN NanoCare

CVE-2026-32389

MEDIUM CVSS 5.4 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-24586 - Newses Plugin

Missing Authorization vulnerability in Themeansar Newses allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Newses: from n/a through 2.0.0.77.

PLUGIN Newses

CVE-2026-24586

MEDIUM CVSS 5.4 2026-05-25
Threat Entry Updated 2026-07-20

CVE-2026-27398 - RSVP and Event Management Plugin

Missing Authorization vulnerability in WP Chill RSVP and Event Management allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RSVP and Event Management: from n/a through 2.7.16.

PLUGIN RSVP and Event Management

CVE-2026-27398

MEDIUM CVSS 5.3 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-27357 - WP Search Analytics Plugin

Missing Authorization vulnerability in Cornel Raiu WP Search Analytics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Search Analytics: from n/a before 1.5.0.

PLUGIN WP Search Analytics

CVE-2026-27357

MEDIUM CVSS 5.3 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-24592 - Auto Affiliate Links Plugin

Missing Authorization vulnerability in Lucian Apostol Auto Affiliate Links allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Auto Affiliate Links: from n/a through 6.8.8.3.

PLUGIN Auto Affiliate Links

CVE-2026-24592

MEDIUM CVSS 5.3 2026-05-25
Threat Entry Updated 2026-07-24

CVE-2026-27346 - B2BKing Plugin

Missing Authorization vulnerability in Kings Plugins B2BKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects B2BKing: from n/a before 5.2.10.

PLUGIN B2BKing

CVE-2026-27346

MEDIUM CVSS 4.9 2026-05-25
Scroll to top