CVE Vulnerability Database

Search and browse 390,396 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8141HIGH7.2The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include...
CVE-2026-6954MEDIUM5.1Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to...
CVE-2026-6953MEDIUM5.1HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an ema...
CVE-2026-13149HIGH7.7brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time comple...
CVE-2026-12610MEDIUM6.4A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free v...
CVE-2026-12076CRITICAL9.3Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, ...
CVE-2026-10763HIGH7PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support fr...
CVE-2025-7406HIGH7.8Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administr...
CVE-2025-24816MEDIUM6.5Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. ...
CVE-2025-24815HIGH7.8Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Succ...
CVE-2026-45822MEDIUM6.6decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' produci...
CVE-2026-12578HIGH8.4The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr...
CVE-2026-9576MEDIUM4.9The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting a...
CVE-2026-56809MEDIUM5.1Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr...
CVE-2026-56808HIGH8.6DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arb...
CVE-2026-56137HIGH8.4RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads ...
CVE-2026-14164HIGH7.5A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive,...
CVE-2026-12819CRITICAL9.3Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro...
CVE-2026-12818CRITICAL9.3Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-...
CVE-2026-12240HIGH8The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2026-11590HIGH8.6The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys b...
CVE-2026-11589HIGH8.8The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, a...
CVE-2026-11581MEDIUM5.9The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's ca...
CVE-2026-8944MEDIUM4.3The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v...
CVE-2026-12560MEDIUM4.4The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...