CVE Vulnerability Database

Search and browse 389,990 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15097MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module ...
CVE-2026-15096MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field...
CVE-2026-14262HIGH8.8The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Byp...
CVE-2026-13250MEDIUM5.3The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3....
CVE-2026-13116MEDIUM4.3The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference ...
CVE-2026-12141MEDIUM4.9The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored C...
CVE-2025-13968MEDIUM6.4The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcod...
CVE-2026-8678MEDIUM4.3The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. Th...
CVE-2026-7544MEDIUM4.3The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i...
CVE-2026-5743MEDIUM6.4The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attribut...
CVE-2026-3367MEDIUM4.4The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App I...
CVE-2026-15338HIGH7.5The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2026-15073MEDIUM6.5The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-15072MEDIUM6.5The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-13353HIGH8.8The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remo...
CVE-2026-13262MEDIUM6.5The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generi...
CVE-2026-13114HIGH7.2The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2026-12426MEDIUM5.3The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2026-10628MEDIUM4.3The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to,...
CVE-2026-13756HIGH8.8The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3...
CVE-2026-11426MEDIUM6.5The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu...
CVE-2026-55175HIGH7.5Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, a...
CVE-2026-44383HIGH8.7Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to de...
CVE-2026-42952HIGH8.7Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could al...
CVE-2026-20744CRITICAL9.8The charging station websocket endpoint accepts connections without proper authentication, which could lead to privileg...