Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total18,226
Critical1,270
High4,357
Medium12,382
Reset
Showing 2621-2640 of 18226 records
Threat Entry Updated 2026-07-24

CVE-2026-39674 - MK Google Directions Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manoj Kumar MK Google Directions google-distance-calculator allows DOM-Based XSS.This issue affects MK Google Directions: from n/a through

PLUGIN MK Google Directions

CVE-2026-39674

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39670 - Visual Link Preview Plugin

Server-Side Request Forgery (SSRF) vulnerability in Brecht Visual Link Preview visual-link-preview allows Server Side Request Forgery.This issue affects Visual Link Preview: from n/a through

PLUGIN Visual Link Preview

CVE-2026-39670

MEDIUM CVSS 6.0 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39667 - Korea SNS Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-Based XSS.This issue affects Korea SNS: from n/a through

PLUGIN Korea SNS

CVE-2026-39667

MEDIUM CVSS 5.9 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39673 - iZooto Plugin

Missing Authorization vulnerability in shrikantkale iZooto izooto-web-push allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iZooto: from n/a through

PLUGIN iZooto

CVE-2026-39673

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39672 - ShipTime: Discounted Shipping Rates Plugin

Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through

PLUGIN ShipTime: Discounted Shipping Rates

CVE-2026-39672

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39669 - NitroPack Plugin

Missing Authorization vulnerability in NitroPack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NitroPack: from n/a through 1.19.3.

PLUGIN NitroPack

CVE-2026-39669

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39668 - Book Previewer for Woocommerce Plugin

Missing Authorization vulnerability in g5theme Book Previewer for Woocommerce book-previewer-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Book Previewer for Woocommerce: from n/a through

PLUGIN Book Previewer for Woocommerce

CVE-2026-39668

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39666 - Hello Bar Popup Builder Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in telepathy Hello Bar Popup Builder hellobar allows DOM-Based XSS.This issue affects Hello Bar Popup Builder: from n/a through

PLUGIN Hello Bar Popup Builder

CVE-2026-39666

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39665 - SEO Friendly Images Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac SEO Friendly Images seo-image allows DOM-Based XSS.This issue affects SEO Friendly Images: from n/a through

PLUGIN SEO Friendly Images

CVE-2026-39665

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39664 - Leadrebel Plugin

Missing Authorization vulnerability in leadrebel Leadrebel leadrebel allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Leadrebel: from n/a through

PLUGIN Leadrebel

CVE-2026-39664

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39663 - TrueBooker Plugin

Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through

PLUGIN TrueBooker

CVE-2026-39663

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39662 - Product Price by Formula for WooCommerce Plugin

Missing Authorization vulnerability in ProWCPlugins Product Price by Formula for WooCommerce product-price-by-formula-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Price by Formula for WooCommerce: from n/a through

PLUGIN Product Price by Formula for WooCommerce

CVE-2026-39662

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39651 - Total Poll Lite Plugin

Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through

PLUGIN Total Poll Lite

CVE-2026-39651

MEDIUM CVSS 6.5 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39654 - WP Simple HTML Sitemap Plugin

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ashish Ajani WP Simple HTML Sitemap wp-simple-html-sitemap allows DOM-Based XSS.This issue affects WP Simple HTML Sitemap: from n/a through

PLUGIN WP Simple HTML Sitemap

CVE-2026-39654

MEDIUM CVSS 5.9 2026-04-08
Threat Entry Updated 2026-07-20

CVE-2026-39658 - Panda Pods Repeater Field Plugin

Missing Authorization vulnerability in Coding Panda Panda Pods Repeater Field panda-pods-repeater-field allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Panda Pods Repeater Field: from n/a through

PLUGIN Panda Pods Repeater Field

CVE-2026-39658

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39657 - leadlovers forms Plugin

Missing Authorization vulnerability in leadlovers leadlovers forms leadlovers-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects leadlovers forms: from n/a through

PLUGIN leadlovers forms

CVE-2026-39657

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39656 - Razorpay for WooCommerce Plugin

Missing Authorization vulnerability in Razorpay Razorpay for WooCommerce woo-razorpay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Razorpay for WooCommerce: from n/a through

PLUGIN Razorpay for WooCommerce

CVE-2026-39656

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39652 - iGMS Direct Booking Plugin

Missing Authorization vulnerability in igms iGMS Direct Booking igms-direct-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects iGMS Direct Booking: from n/a through

PLUGIN iGMS Direct Booking

CVE-2026-39652

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39650 - UnitechPay Plugin

Missing Authorization vulnerability in Unitech Web UnitechPay unitechpay-paiements-mobile-money allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UnitechPay: from n/a through

PLUGIN UnitechPay

CVE-2026-39650

MEDIUM CVSS 5.3 2026-04-08
Threat Entry Updated 2026-07-24

CVE-2026-39653 - Video Conferencing with Zoom Plugin

Missing Authorization vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Video Conferencing with Zoom: from n/a through

PLUGIN Video Conferencing with Zoom

CVE-2026-39653

MEDIUM CVSS 4.3 2026-04-08
Scroll to top