CVE Vulnerability Database
Search and browse 390,135 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11896 | MEDIUM | 5.3 | 0.5% | Jul 2, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all... |
| CVE-2026-10104 | MEDIUM | 4.4 | 0.3% | Jul 2, 2026 | The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_t... |
| CVE-2026-9563 | HIGH | 7.5 | 0.4% | Jul 2, 2026 | In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max... |
| CVE-2026-8147 | HIGH | 8.1 | 0.3% | Jul 2, 2026 | In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper author... |
| CVE-2026-33592 | HIGH | 7.5 | 0.4% | Jul 2, 2026 | An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The ser... |
| CVE-2026-5821 | HIGH | 8.1 | 0.4% | Jul 2, 2026 | The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4.... |
| CVE-2026-5348 | MEDIUM | 5.3 | 0.3% | Jul 2, 2026 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di... |
| CVE-2026-14249 | HIGH | 7.5 | 0.3% | Jul 2, 2026 | The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the... |
| CVE-2026-13704 | MEDIUM | 6.4 | 0.2% | Jul 2, 2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-13357 | MEDIUM | 4.9 | 0.3% | Jul 2, 2026 | The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions... |
| CVE-2026-11965 | MEDIUM | 6.5 | 0.1% | Jul 2, 2026 | The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating ... |
| CVE-2026-11781 | LOW | 2.7 | 0.1% | Jul 2, 2026 | The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by... |
| CVE-2026-11600 | MEDIUM | 4.3 | 0.2% | Jul 2, 2026 | The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access o... |
| CVE-2026-11592 | MEDIUM | 4.3 | 0.3% | Jul 2, 2026 | The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for W... |
| CVE-2026-11578 | LOW | 2.7 | 0.1% | Jul 2, 2026 | The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to th... |
| CVE-2026-10089 | MEDIUM | 6.4 | 0.2% | Jul 2, 2026 | The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key ... |
| CVE-2026-10077 | MEDIUM | 6.8 | 0.2% | Jul 2, 2026 | The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML a... |
| CVE-2026-57278 | HIGH | 8.3 | 0.3% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
| CVE-2026-57277 | HIGH | 8.3 | 0.3% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
| CVE-2026-57276 | HIGH | 8.3 | 0.3% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
| CVE-2026-57275 | HIGH | 8.3 | 0.3% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
| CVE-2026-57274 | HIGH | 8.3 | 0.3% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
| CVE-2026-57273 | HIGH | 8.3 | 0.3% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
| CVE-2026-57272 | HIGH | 8.3 | 0.2% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
| CVE-2026-57271 | HIGH | 8.3 | 0.2% | Jul 2, 2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b... |
