CVE Vulnerability Database
Search and browse 390,226 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7838 | HIGH | 8.8 | 1.2% | Jul 1, 2026 | UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failu... |
| CVE-2026-7831 | HIGH | 7.6 | 0.4% | Jul 1, 2026 | UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v... |
| CVE-2026-7830 | HIGH | 7.4 | 0.2% | Jul 1, 2026 | UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut... |
| CVE-2026-7829 | HIGH | 7.2 | 0.5% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In r... |
| CVE-2026-7828 | MEDIUM | 5.3 | 0.8% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains an integer overflow in the HTTP request logging path. In repeater/webgui/sett... |
| CVE-2026-7517 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a... |
| CVE-2026-6070 | CRITICAL | 9.1 | 0.4% | Jul 1, 2026 | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to... |
| CVE-2026-58519 | MEDIUM | 5.4 | 0.3% | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-58518 | MEDIUM | 6.3 | 0.2% | Jul 1, 2026 | Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows... |
| CVE-2026-44042 | LOW | 3.7 | 0.3% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentic... |
| CVE-2026-44041 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp... |
| CVE-2026-44040 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication chal... |
| CVE-2026-2387 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi... |
| CVE-2026-13731 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-13468 | HIGH | 7.5 | 0.4% | Jul 1, 2026 | The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization ... |
| CVE-2026-13443 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2026-13246 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-13015 | MEDIUM | 6.1 | 0.2% | Jul 1, 2026 | The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' ... |
| CVE-2026-12923 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3... |
| CVE-2026-12904 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Ob... |
| CVE-2026-12902 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas... |
| CVE-2026-12135 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' ... |
| CVE-2026-12133 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authori... |
| CVE-2026-12127 | MEDIUM | 5.3 | 0.3% | Jul 1, 2026 | The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu... |
| CVE-2026-12113 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
