CVE Vulnerability Database

Search and browse 390,049 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14495HIGH8.8The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all vers...
CVE-2026-14489HIGH8.8The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2026-12153CRITICAL9.8The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1....
CVE-2026-12097MEDIUM5.3The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2...
CVE-2026-12041MEDIUM4.4The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin ...
CVE-2026-11798MEDIUM6.1The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Refle...
CVE-2026-10570MEDIUM6.4The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repea...
CVE-2026-9842HIGH7.5The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,...
CVE-2026-9701CRITICAL9.8The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and includ...
CVE-2026-14487CRITICAL9.1The Simple Coherent Form plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val...
CVE-2026-14482HIGH8.8The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The v...
CVE-2026-14244HIGH7.5The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu...
CVE-2026-14158HIGH8.8The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including...
CVE-2026-60002CRITICAL9.4ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This ...
CVE-2026-60001MEDIUM6.5sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVE-2026-60000HIGH7.5sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive au...
CVE-2026-59999HIGH7.5In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not...
CVE-2026-59998MEDIUM6.5sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th...
CVE-2026-59997MEDIUM5.4internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important ...
CVE-2026-59996MEDIUM5.4scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee...
CVE-2026-59995MEDIUM5.4sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u...
CVE-2026-56843CRITICAL9.9Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo...
CVE-2026-55438MEDIUM6.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7...
CVE-2026-55437MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7...
CVE-2026-55436HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr...