CVE Vulnerability Database

Search and browse 375,689 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14859The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a...
CVE-2026-14858The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi...
CVE-2026-14857The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his...
CVE-2026-13613The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using ...
CVE-2026-13612The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al...
CVE-2026-13177The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user...
CVE-2026-13171The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han...
CVE-2026-13168The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users...
CVE-2026-12976The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a...
CVE-2026-64954HIGH8.2Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th...
CVE-2026-12235MEDIUM6.3The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p...
CVE-2026-12234HIGH7.8The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn...
CVE-2026-12233MEDIUM5.9The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre...
CVE-2026-12232MEDIUM6.1The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal...
CVE-2025-15687MEDIUM4.3A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF ...
CVE-2026-9318MEDIUM5.4tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows...
CVE-2026-19588MEDIUM6.5Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
CVE-2026-19587MEDIUM6.5Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
CVE-2026-18961HIGH8.1The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnera...
CVE-2025-15686MEDIUM4.3A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the com...
CVE-2025-15685MEDIUM6.3A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the componen...
CVE-2025-15684MEDIUM5.3A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com...
CVE-2026-73122HIGH7.7A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vuln...
CVE-2026-72526CRITICAL9.9A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-man...
CVE-2026-70398CRITICAL9.6A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerabil...