CVE Vulnerability Database

Search and browse 390,135 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-11896MEDIUM5.3The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all...
CVE-2026-10104MEDIUM4.4The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_t...
CVE-2026-9563HIGH7.5In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default max...
CVE-2026-8147HIGH8.1In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper author...
CVE-2026-33592HIGH7.5An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The ser...
CVE-2026-5821HIGH8.1The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4....
CVE-2026-5348MEDIUM5.3The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di...
CVE-2026-14249HIGH7.5The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the...
CVE-2026-13704MEDIUM6.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-13357MEDIUM4.9The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions...
CVE-2026-11965MEDIUM6.5The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating ...
CVE-2026-11781LOW2.7The Adminify WordPress plugin before 4.2.10 does not perform per-user read-capability checks on the results returned by...
CVE-2026-11600MEDIUM4.3The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access o...
CVE-2026-11592MEDIUM4.3The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for W...
CVE-2026-11578LOW2.7The Fluent Forms WordPress plugin before 6.2.5 does not properly restrict the deletion of form submission entries to th...
CVE-2026-10089MEDIUM6.4The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key ...
CVE-2026-10077MEDIUM6.8The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML a...
CVE-2026-57278HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...
CVE-2026-57277HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...
CVE-2026-57276HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...
CVE-2026-57275HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...
CVE-2026-57274HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...
CVE-2026-57273HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...
CVE-2026-57272HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...
CVE-2026-57271HIGH8.3GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can b...