CVE Vulnerability Database
Search and browse 391,088 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11883 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authent... |
| CVE-2026-11880 | LOW | 3.1 | 0.1% | Jul 1, 2026 | The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription canc... |
| CVE-2026-11823 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date... |
| CVE-2026-11794 | HIGH | 8.1 | 0.1% | Jul 1, 2026 | The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress... |
| CVE-2026-11570 | MEDIUM | 4.2 | 0.2% | Jul 1, 2026 | The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an ... |
| CVE-2026-11568 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status... |
| CVE-2026-11562 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions,... |
| CVE-2026-10750 | HIGH | 8.1 | 0.2% | Jul 1, 2026 | The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after ... |
| CVE-2025-15666 | MEDIUM | 5.3 | 0.1% | Jul 1, 2026 | A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili... |
| CVE-2026-9107 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-7840 | CRITICAL | 9.8 | 1.2% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The func... |
| CVE-2026-7839 | CRITICAL | 9.1 | 0.3% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea... |
| CVE-2026-7838 | HIGH | 8.8 | 1.2% | Jul 1, 2026 | UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failu... |
| CVE-2026-7831 | HIGH | 7.6 | 0.4% | Jul 1, 2026 | UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v... |
| CVE-2026-7830 | HIGH | 7.4 | 0.2% | Jul 1, 2026 | UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut... |
| CVE-2026-7829 | HIGH | 7.2 | 0.5% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In r... |
| CVE-2026-7828 | MEDIUM | 5.3 | 0.8% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains an integer overflow in the HTTP request logging path. In repeater/webgui/sett... |
| CVE-2026-7517 | HIGH | 7.2 | 0.2% | Jul 1, 2026 | The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a... |
| CVE-2026-6070 | CRITICAL | 9.1 | 0.4% | Jul 1, 2026 | The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to... |
| CVE-2026-58519 | MEDIUM | 5.4 | 0.3% | Jul 1, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-58518 | MEDIUM | 6.3 | 0.2% | Jul 1, 2026 | Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows... |
| CVE-2026-44042 | LOW | 3.7 | 0.3% | Jul 1, 2026 | UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentic... |
| CVE-2026-44041 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp... |
| CVE-2026-44040 | MEDIUM | 6.5 | 0.2% | Jul 1, 2026 | UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication chal... |
| CVE-2026-2387 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi... |
