CVE Vulnerability Database

Search and browse 390,014 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-53363CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_c...
CVE-2026-58225LOW2.1SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject...
CVE-2026-14461MEDIUM5.1mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT ...
CVE-2026-9857MEDIUM4.3The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. T...
CVE-2026-41880CRITICAL9R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command exe...
CVE-2026-41879HIGH8.2R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password...
CVE-2026-41878HIGH7.1R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The appl...
CVE-2026-41877MEDIUM5.1R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML an...
CVE-2026-41876HIGH8.7R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co...
CVE-2026-15378CRITICAL9.3A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind...
CVE-2026-15028LOW3.9A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp...
CVE-2026-13710MEDIUM6.4The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul...
CVE-2026-13247MEDIUM6.4The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to...
CVE-2026-13010MEDIUM6.5The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-12918MEDIUM4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-11990MEDIUM5.3The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-9838MEDIUM6.1The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter i...
CVE-2026-6802MEDIUM5.3The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, a...
CVE-2026-6440MEDIUM4.3The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cro...
CVE-2026-3907MEDIUM6.4The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all ve...
CVE-2026-1946MEDIUM4.3The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2026-15104MEDIUM6.5The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g...
CVE-2026-15026MEDIUM4.3The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve...
CVE-2026-14475MEDIUM4.9The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ...
CVE-2026-12955MEDIUM4.3The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil...