Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,226
Critical1,270
High4,357
Medium12,382
Reset
Showing 2601-2620 of 18226 records
Threat Entry Updated 2026-07-24

CVE-2026-39695 - Podigee Plugin

Server-Side Request Forgery (SSRF) vulnerability in podigee Podigee podigee allows Server Side Request Forgery.This issue affects Podigee: from n/a through

PLUGIN Podigee

CVE-2026-39695

MEDIUM CVSS 5.4 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39694 - Simply Schedule Appointments Plugin

Missing Authorization vulnerability in NSquared Simply Schedule Appointments simply-schedule-appointments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simply Schedule Appointments: from n/a through

PLUGIN Simply Schedule Appointments

CVE-2026-39694

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39691 - Cryptocurrency Donation Box – Bitcoin & Crypto Donations Plugin

Missing Authorization vulnerability in AdAstraCrypto Cryptocurrency Donation Box – Bitcoin & Crypto Donations cryptocurrency-donation-box allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cryptocurrency Donation Box – Bitcoin & Crypto Donations: from n/a through

PLUGIN Cryptocurrency Donation Box – Bitcoin & Crypto Donations

CVE-2026-39691

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39690 - Author Avatars List/Block Plugin

Missing Authorization vulnerability in Paul Bearne Author Avatars List/Block author-avatars allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Author Avatars List/Block: from n/a through

PLUGIN Author Avatars List/Block

CVE-2026-39690

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39684 - OrganicFood Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnTheme OrganicFood organicfood allows PHP Local File Inclusion.This issue affects OrganicFood: from n/a through

PLUGIN OrganicFood

CVE-2026-39684

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39683 - Garden Gnome Package Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chief Gnome Garden Gnome Package garden-gnome-package allows DOM-Based XSS.This issue affects Garden Gnome Package: from n/a through

PLUGIN Garden Gnome Package

CVE-2026-39683

MEDIUM CVSS 5.9 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39689 - eShipper Commerce Plugin

Missing Authorization vulnerability in eshipper eShipper Commerce eshipper-commerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects eShipper Commerce: from n/a through

PLUGIN eShipper Commerce

CVE-2026-39689

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39688 - WP Frontend Profile Plugin

Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through

PLUGIN WP Frontend Profile

CVE-2026-39688

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39687 - Rapid Car Check Vehicle Data Plugin

Missing Authorization vulnerability in Rapid Car Check Rapid Car Check Vehicle Data free-vehicle-data-uk allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Rapid Car Check Vehicle Data: from n/a through

PLUGIN Rapid Car Check Vehicle Data

CVE-2026-39687

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39686 - BSK PDF Manager Plugin

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in bannersky BSK PDF Manager bsk-pdf-manager allows Retrieve Embedded Sensitive Data.This issue affects BSK PDF Manager: from n/a through

PLUGIN BSK PDF Manager

CVE-2026-39686

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39685 - The Moneytizer Plugin

Missing Authorization vulnerability in lvaudore The Moneytizer the-moneytizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Moneytizer: from n/a through

PLUGIN The Moneytizer

CVE-2026-39685

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39682 - linkPizza-Manager Plugin

Missing Authorization vulnerability in Arjan Pronk linkPizza-Manager linkpizza-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects linkPizza-Manager: from n/a through

PLUGIN linkPizza-Manager

CVE-2026-39682

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39681 - Homeo Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Homeo homeo allows PHP Local File Inclusion.This issue affects Homeo: from n/a through

PLUGIN Homeo

CVE-2026-39681

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39679 - Freeio Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ApusTheme Freeio freeio allows PHP Local File Inclusion.This issue affects Freeio: from n/a through

PLUGIN Freeio

CVE-2026-39679

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39677 - Emphires Plugin

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through

PLUGIN Emphires

CVE-2026-39677

HIGH CVSS 7.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39680 - Diet Calorie Calculator Plugin

Missing Authorization vulnerability in MWP Development Diet Calorie Calculator diet-calorie-calculator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Diet Calorie Calculator: from n/a through

PLUGIN Diet Calorie Calculator

CVE-2026-39680

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39678 - Pinpoint Booking System Plugin

Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pinpoint Booking System: from n/a through

PLUGIN Pinpoint Booking System

CVE-2026-39678

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-20

CVE-2026-39676 - Download Manager Plugin

Missing Authorization vulnerability in Shahjada Download Manager download-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download Manager: from n/a through

PLUGIN Download Manager

CVE-2026-39676

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39675 - Court Reservation Plugin

Missing Authorization vulnerability in webmuehle Court Reservation court-reservation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Court Reservation: from n/a through

PLUGIN Court Reservation

CVE-2026-39675

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39671 - Extra Fees Plugin for WooCommerce

Cross-Site Request Forgery (CSRF) vulnerability in Dotstore Extra Fees Plugin for WooCommerce woo-conditional-product-fees-for-checkout allows Cross Site Request Forgery.This issue affects Extra Fees Plugin for WooCommerce: from n/a through

PLUGIN Extra Fees Plugin for WooCommerce

CVE-2026-39671

HIGH CVSS 7.1 2026-04-08
Scroll to top