CVE Vulnerability Database
Search and browse 390,041 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22927 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. |
| CVE-2026-15053 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Tanium addressed a denial of service vulnerability in Tanium Server. |
| CVE-2026-15035 | HIGH | 7.8 | 0.6% | Jul 8, 2026 | A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm... |
| CVE-2026-15034 | MEDIUM | 4.3 | — | Jul 8, 2026 | A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some ... |
| CVE-2026-15033 | MEDIUM | 6.3 | — | Jul 8, 2026 | A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the f... |
| CVE-2026-8315 | MEDIUM | 5.4 | — | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-8310 | MEDIUM | 6.1 | — | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-8307 | CRITICAL | 9.8 | — | Jul 8, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-6820 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema... |
| CVE-2026-6740 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-6459 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-5459 | MEDIUM | 5.3 | — | Jul 8, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-5356 | HIGH | 7.5 | — | Jul 8, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input... |
| CVE-2026-14454 | CRITICAL | 9.8 | 0.4% | Jul 8, 2026 | Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD ... |
| CVE-2026-12002 | MEDIUM | 4.7 | — | Jul 8, 2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2026-6854 | HIGH | 7.5 | — | Jul 8, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ... |
| CVE-2026-6818 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe... |
| CVE-2026-6742 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ... |
| CVE-2026-6371 | MEDIUM | 4.8 | 0.1% | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc... |
| CVE-2026-6230 | HIGH | 7.5 | — | Jul 8, 2026 | The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve... |
| CVE-2026-41042 | CRITICAL | 9.1 | — | Jul 8, 2026 | Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java... |
| CVE-2026-3688 | HIGH | 8.1 | — | Jul 8, 2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure... |
| CVE-2026-14250 | MEDIUM | 6.3 | — | Jul 8, 2026 | The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu... |
| CVE-2026-12936 | MEDIUM | 4.9 | — | Jul 8, 2026 | The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ... |
| CVE-2025-14785 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor... |
