CVE Vulnerability Database

Search and browse 376,500 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16589HIGH7.7The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL sta...
CVE-2026-16578HIGH7.5The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does n...
CVE-2026-16574MEDIUM5.4The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that ...
CVE-2026-16562MEDIUM6.5The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics ...
CVE-2026-16559MEDIUM6.8The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur...
CVE-2026-16558MEDIUM5.4The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it...
CVE-2026-16535MEDIUM6.1The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a r...
CVE-2026-16282MEDIUM5.3The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against t...
CVE-2026-16269MEDIUM4.8The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica...
CVE-2026-16267HIGH8.1The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from...
CVE-2026-14526CRITICAL9.8The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and...
CVE-2026-18988MEDIUM6.4The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block a...
CVE-2026-13505HIGH8.7In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X ser...
CVE-2026-8798HIGH8.7In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried ...
CVE-2026-52880HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable...
CVE-2026-52879HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-mess...
CVE-2026-52878HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a...
CVE-2026-49343MEDIUM5.9Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie...
CVE-2026-48122MEDIUM5.4Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP...
CVE-2026-48120HIGH8.6Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be ...
CVE-2026-48047MEDIUM5.9XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to ...
CVE-2026-48026HIGH8.7lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th...
CVE-2026-47249HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling...
CVE-2026-47127MEDIUM6.5Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR...
CVE-2026-46409CRITICAL9.6OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v...