CVE Vulnerability Database
Search and browse 390,014 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53363 | CRITICAL | 9.8 | 0.3% | Jul 10, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_c... |
| CVE-2026-58225 | LOW | 2.1 | — | Jul 10, 2026 | SQL Injection vulnerability in elixir-ecto postgrex allows an attacker who can influence a LISTEN channel name to inject... |
| CVE-2026-14461 | MEDIUM | 5.1 | — | Jul 10, 2026 | mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT ... |
| CVE-2026-9857 | MEDIUM | 4.3 | 0.5% | Jul 10, 2026 | The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. T... |
| CVE-2026-41880 | CRITICAL | 9 | 1.3% | Jul 10, 2026 | R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command exe... |
| CVE-2026-41879 | HIGH | 8.2 | 0.3% | Jul 10, 2026 | R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password... |
| CVE-2026-41878 | HIGH | 7.1 | 0.5% | Jul 10, 2026 | R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The appl... |
| CVE-2026-41877 | MEDIUM | 5.1 | 0.4% | Jul 10, 2026 | R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML an... |
| CVE-2026-41876 | HIGH | 8.7 | 1.2% | Jul 10, 2026 | R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co... |
| CVE-2026-15378 | CRITICAL | 9.3 | 0.5% | Jul 10, 2026 | A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind... |
| CVE-2026-15028 | LOW | 3.9 | 0.3% | Jul 10, 2026 | A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a sp... |
| CVE-2026-13710 | MEDIUM | 6.4 | 0.4% | Jul 10, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-13247 | MEDIUM | 6.4 | 0.3% | Jul 10, 2026 | The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to... |
| CVE-2026-13010 | MEDIUM | 6.5 | 0.4% | Jul 10, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ... |
| CVE-2026-12918 | MEDIUM | 4.9 | 0.3% | Jul 10, 2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to... |
| CVE-2026-11990 | MEDIUM | 5.3 | 0.6% | Jul 10, 2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in al... |
| CVE-2026-9838 | MEDIUM | 6.1 | 0.3% | Jul 10, 2026 | The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter i... |
| CVE-2026-6802 | MEDIUM | 5.3 | 0.2% | Jul 10, 2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, a... |
| CVE-2026-6440 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cro... |
| CVE-2026-3907 | MEDIUM | 6.4 | 0.2% | Jul 10, 2026 | The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all ve... |
| CVE-2026-1946 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2026-15104 | MEDIUM | 6.5 | 0.3% | Jul 10, 2026 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to g... |
| CVE-2026-15026 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve... |
| CVE-2026-14475 | MEDIUM | 4.9 | 0.3% | Jul 10, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via ... |
| CVE-2026-12955 | MEDIUM | 4.3 | 0.2% | Jul 10, 2026 | The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil... |
