CVE Vulnerability Database

Search and browse 390,226 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12435MEDIUM4.3The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in a...
CVE-2026-12408MEDIUM4.3The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Co...
CVE-2026-12224HIGH8.8The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve...
CVE-2026-12158HIGH8.8The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2026-11387CRITICAL9.8The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-10540MEDIUM5.6The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offl...
CVE-2026-10539CRITICAL9.5A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain con...
CVE-2026-10538HIGH8.9Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe...
CVE-2026-10096MEDIUM4.3The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin...
CVE-2026-1239HIGH7.5The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access...
CVE-2026-14193HIGH7.5DVP80ES300T with Improper Validation of Array Index Vulnerability
CVE-2026-12579HIGH7.4AS228T with Authentication Bypass Vulnerability
CVE-2026-11887MEDIUM4.3The Salon Booking System WordPress plugin before 10.30.20 does not have proper authorisation checks on one of its AJAX ...
CVE-2026-11883HIGH7.2The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authent...
CVE-2026-11880LOW3.1The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription canc...
CVE-2026-11823HIGH7.5The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date...
CVE-2026-11794HIGH8.1The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress...
CVE-2026-11570MEDIUM4.2The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an ...
CVE-2026-11568HIGH7.5The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status...
CVE-2026-11562MEDIUM4.3The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions,...
CVE-2026-10750HIGH8.1The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after ...
CVE-2025-15666MEDIUM5.3A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili...
CVE-2026-9107MEDIUM6.4The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-7840CRITICAL9.8UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The func...
CVE-2026-7839CRITICAL9.1UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea...