CVE Vulnerability Database
Search and browse 389,990 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15097 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module ... |
| CVE-2026-15096 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field... |
| CVE-2026-14262 | HIGH | 8.8 | 0.4% | Jul 11, 2026 | The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp... |
| CVE-2026-13250 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3.... |
| CVE-2026-13116 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference ... |
| CVE-2026-12141 | MEDIUM | 4.9 | 0.2% | Jul 11, 2026 | The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C... |
| CVE-2025-13968 | MEDIUM | 6.4 | 0.2% | Jul 11, 2026 | The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod... |
| CVE-2026-8678 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. Th... |
| CVE-2026-7544 | MEDIUM | 4.3 | 0.2% | Jul 11, 2026 | The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i... |
| CVE-2026-5743 | MEDIUM | 6.4 | 0.3% | Jul 11, 2026 | The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribut... |
| CVE-2026-3367 | MEDIUM | 4.4 | 0.3% | Jul 11, 2026 | The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App I... |
| CVE-2026-15338 | HIGH | 7.5 | 0.6% | Jul 11, 2026 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to... |
| CVE-2026-15073 | MEDIUM | 6.5 | 0.2% | Jul 11, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-15072 | MEDIUM | 6.5 | 0.3% | Jul 11, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-13353 | HIGH | 8.8 | 0.6% | Jul 11, 2026 | The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo... |
| CVE-2026-13262 | MEDIUM | 6.5 | 0.4% | Jul 11, 2026 | The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generi... |
| CVE-2026-13114 | HIGH | 7.2 | 0.2% | Jul 11, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2026-12426 | MEDIUM | 5.3 | 0.3% | Jul 11, 2026 | The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ... |
| CVE-2026-10628 | MEDIUM | 4.3 | 0.3% | Jul 11, 2026 | The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,... |
| CVE-2026-13756 | HIGH | 8.8 | 0.3% | Jul 11, 2026 | The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3... |
| CVE-2026-11426 | MEDIUM | 6.5 | 0.3% | Jul 11, 2026 | The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu... |
| CVE-2026-55175 | HIGH | 7.5 | 0.6% | Jul 10, 2026 | Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, a... |
| CVE-2026-44383 | HIGH | 8.7 | 0.6% | Jul 10, 2026 | Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to de... |
| CVE-2026-42952 | HIGH | 8.7 | 0.4% | Jul 10, 2026 | Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could al... |
| CVE-2026-20744 | CRITICAL | 9.8 | 0.5% | Jul 10, 2026 | The charging station websocket endpoint accepts connections without proper authentication, which could lead to privileg... |
