CVE Vulnerability Database
Search and browse 390,033 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13011 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner... |
| CVE-2026-12418 | MEDIUM | 5.3 | 0.2% | Jul 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-12406 | MEDIUM | 5.3 | 0.3% | Jul 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-12170 | MEDIUM | 6.4 | 0.3% | Jul 9, 2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
| CVE-2026-11359 | MEDIUM | 4.3 | 0.2% | Jul 9, 2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerab... |
| CVE-2026-47840 | CRITICAL | 9.3 | 0.1% | Jul 9, 2026 | A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate fro... |
| CVE-2026-47831 | HIGH | 7.7 | 0.2% | Jul 9, 2026 | Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-... |
| CVE-2026-47830 | HIGH | 8.8 | 0.1% | Jul 9, 2026 | Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege ... |
| CVE-2026-47829 | HIGH | 7.8 | 0.3% | Jul 9, 2026 | Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-s... |
| CVE-2026-47828 | HIGH | 8.8 | 0.1% | Jul 9, 2026 | During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new ... |
| CVE-2026-47826 | CRITICAL | 9.1 | 0.3% | Jul 9, 2026 | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi... |
| CVE-2026-12517 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe... |
| CVE-2026-12516 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performe... |
| CVE-2026-12270 | MEDIUM | 6.5 | 0.1% | Jul 9, 2026 | The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belong... |
| CVE-2026-11875 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session co... |
| CVE-2026-11869 | MEDIUM | 5.3 | 0.1% | Jul 9, 2026 | The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-proces... |
| CVE-2026-11571 | HIGH | 7.5 | 0.1% | Jul 9, 2026 | The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-not... |
| CVE-2026-5523 | HIGH | 8.8 | 0.3% | Jul 9, 2026 | The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.... |
| CVE-2026-41857 | HIGH | 7.8 | 0.1% | Jul 9, 2026 | A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the ope... |
| CVE-2026-15138 | MEDIUM | 6.3 | 0.3% | Jul 9, 2026 | A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validat... |
| CVE-2026-47646 | MEDIUM | 6.1 | 0.5% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allo... |
| CVE-2026-15137 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code... |
| CVE-2026-15135 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the f... |
| CVE-2026-15134 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is... |
| CVE-2026-59723 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.30, the Cline Hub dashboard... |
