CVE Vulnerability Database

Search and browse 390,033 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13011MEDIUM6.5The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner...
CVE-2026-12418MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12406MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12170MEDIUM6.4The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2026-11359MEDIUM4.3The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerab...
CVE-2026-47840CRITICAL9.3A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate fro...
CVE-2026-47831HIGH7.7Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-...
CVE-2026-47830HIGH8.8Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege ...
CVE-2026-47829HIGH7.8Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s...
CVE-2026-47828HIGH8.8During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new ...
CVE-2026-47826CRITICAL9.1The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi...
CVE-2026-12517MEDIUM5.3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe...
CVE-2026-12516MEDIUM5.3The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe...
CVE-2026-12270MEDIUM6.5The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belong...
CVE-2026-11875MEDIUM5.3The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session co...
CVE-2026-11869MEDIUM5.3The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-proces...
CVE-2026-11571HIGH7.5The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-not...
CVE-2026-5523HIGH8.8The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1....
CVE-2026-41857HIGH7.8A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the ope...
CVE-2026-15138MEDIUM6.3A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validat...
CVE-2026-47646MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo...
CVE-2026-15137HIGH7.3A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code...
CVE-2026-15135HIGH7.3A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the f...
CVE-2026-15134HIGH7.3A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is...
CVE-2026-59723HIGH8.8Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.30, the Cline Hub dashboard...