CVE Vulnerability Database

Search and browse 390,041 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-22927HIGH7.8Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CVE-2026-15053HIGH7.5Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-15035HIGH7.8A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm...
CVE-2026-15034MEDIUM4.3A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some ...
CVE-2026-15033MEDIUM6.3A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the f...
CVE-2026-8315MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig...
CVE-2026-8310MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig...
CVE-2026-8307CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig...
CVE-2026-6820HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema...
CVE-2026-6740MEDIUM6.4The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-6459MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-5459MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-5356HIGH7.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input...
CVE-2026-14454CRITICAL9.8Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD ...
CVE-2026-12002MEDIUM4.7The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2026-6854HIGH7.5The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ...
CVE-2026-6818HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe...
CVE-2026-6742MEDIUM6.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ...
CVE-2026-6371MEDIUM4.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc...
CVE-2026-6230HIGH7.5The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve...
CVE-2026-41042CRITICAL9.1Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java...
CVE-2026-3688HIGH8.1The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure...
CVE-2026-14250MEDIUM6.3The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and inclu...
CVE-2026-12936MEDIUM4.9The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the ...
CVE-2025-14785MEDIUM6.4The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor...