CVE Vulnerability Database
Search and browse 390,396 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8141 | HIGH | 7.2 | 0.3% | Jun 30, 2026 | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include... |
| CVE-2026-6954 | MEDIUM | 5.1 | 0.4% | Jun 30, 2026 | Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to... |
| CVE-2026-6953 | MEDIUM | 5.1 | 0.4% | Jun 30, 2026 | HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an ema... |
| CVE-2026-13149 | HIGH | 7.7 | 0.4% | Jun 30, 2026 | brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time comple... |
| CVE-2026-12610 | MEDIUM | 6.4 | 0.1% | Jun 30, 2026 | A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free v... |
| CVE-2026-12076 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote, ... |
| CVE-2026-10763 | HIGH | 7 | 0.3% | Jun 30, 2026 | PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support fr... |
| CVE-2025-7406 | HIGH | 7.8 | 0.1% | Jun 30, 2026 | Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administr... |
| CVE-2025-24816 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. ... |
| CVE-2025-24815 | HIGH | 7.8 | 0.2% | Jun 30, 2026 | Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Succ... |
| CVE-2026-45822 | MEDIUM | 6.6 | 0.3% | Jun 30, 2026 | decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' produci... |
| CVE-2026-12578 | HIGH | 8.4 | 0.4% | Jun 30, 2026 | The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr... |
| CVE-2026-9576 | MEDIUM | 4.9 | 0.1% | Jun 30, 2026 | The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting a... |
| CVE-2026-56809 | MEDIUM | 5.1 | 0.3% | Jun 30, 2026 | Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr... |
| CVE-2026-56808 | HIGH | 8.6 | 1.6% | Jun 30, 2026 | DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arb... |
| CVE-2026-56137 | HIGH | 8.4 | 0.7% | Jun 30, 2026 | RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads ... |
| CVE-2026-14164 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive,... |
| CVE-2026-12819 | CRITICAL | 9.3 | 0.3% | Jun 30, 2026 | Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro... |
| CVE-2026-12818 | CRITICAL | 9.3 | 0.3% | Jun 30, 2026 | Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-... |
| CVE-2026-12240 | HIGH | 8 | 0.3% | Jun 30, 2026 | The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2026-11590 | HIGH | 8.6 | 0.2% | Jun 30, 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys b... |
| CVE-2026-11589 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, a... |
| CVE-2026-11581 | MEDIUM | 5.9 | 0.2% | Jun 30, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's ca... |
| CVE-2026-8944 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v... |
| CVE-2026-12560 | MEDIUM | 4.4 | 0.2% | Jun 30, 2026 | The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
