CVE Vulnerability Database

Search and browse 390,029 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8848HIGH7.2The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
CVE-2026-7558MEDIUM5.3The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access...
CVE-2026-6910MEDIUM6.4The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `boo...
CVE-2026-59269LOW3.8A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in ...
CVE-2026-57111HIGH7.5Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFi...
CVE-2026-4653MEDIUM6.4The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin...
CVE-2026-33390HIGH8.1An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors r...
CVE-2026-31985HIGH8.3When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disab...
CVE-2026-31984HIGH8.7A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functional...
CVE-2026-31983MEDIUM6.9A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attac...
CVE-2026-31982HIGH7.1An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of...
CVE-2026-31981MEDIUM4.8A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation ...
CVE-2026-15000HIGH7.2The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp...
CVE-2026-14343MEDIUM6.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after...
CVE-2026-14342MEDIUM4.9The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to...
CVE-2026-14245CRITICAL9.8The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2026-13771MEDIUM6.4The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Short...
CVE-2026-13450MEDIUM5.3The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-13334MEDIUM6.1The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all v...
CVE-2026-13253MEDIUM6.4The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attr...
CVE-2026-13080MEDIUM6.6The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Lo...
CVE-2026-13011MEDIUM6.5The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner...
CVE-2026-12418MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12406MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12170MEDIUM6.4The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...