CVE Vulnerability Database

Search and browse 391,088 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-11883HIGH7.2The WebAuthn Provider for Two Factor WordPress plugin before 2.5.6 does not correctly validate the second-factor authent...
CVE-2026-11880LOW3.1The Fluent Forms WordPress plugin before 6.2.1 does not properly verify ownership before processing a subscription canc...
CVE-2026-11823HIGH7.5The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date...
CVE-2026-11794HIGH8.1The Advanced Form Integration — Connect Forms to 200+ Apps WordPress plugin before 2.1.1 does not restrict the WordPress...
CVE-2026-11570MEDIUM4.2The User Submitted Posts WordPress plugin before 20260608 does not escape a submitted value before outputting it in an ...
CVE-2026-11568HIGH7.5The Product Configurator for WooCommerce WordPress plugin before 1.7.3 does not perform any authorisation or post-status...
CVE-2026-11562MEDIUM4.3The WS Form LITE WordPress plugin before 1.11.8 does not have a capability check on one of its settings-update actions,...
CVE-2026-10750HIGH8.1The Royal MCP WordPress plugin before 1.4.26 does not perform capability checks on the majority of its MCP tools after ...
CVE-2025-15666MEDIUM5.3A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili...
CVE-2026-9107MEDIUM6.4The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-7840CRITICAL9.8UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The func...
CVE-2026-7839CRITICAL9.1UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repea...
CVE-2026-7838HIGH8.8UltraVNC viewer through 1.8.2.2 contains an integer overflow leading to a heap buffer overflow in the RFB protocol failu...
CVE-2026-7831HIGH7.6UltraVNC viewer through 1.8.2.2 contains an off-by-one stack buffer overflow in the RFB ServerInit message handler. In v...
CVE-2026-7830HIGH7.4UltraVNC through 1.8.2.2 uses inadequate cryptography in the MS-Logon II authentication scheme (rfbUltraVNC_MsLogonIIAut...
CVE-2026-7829HIGH7.2UltraVNC repeater through 1.8.2.2 contains a post-authentication out-of-bounds write in the allow/deny rule parser. In r...
CVE-2026-7828MEDIUM5.3UltraVNC repeater through 1.8.2.2 contains an integer overflow in the HTTP request logging path. In repeater/webgui/sett...
CVE-2026-7517HIGH7.2The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a...
CVE-2026-6070CRITICAL9.1The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to...
CVE-2026-58519MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-58518MEDIUM6.3Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows...
CVE-2026-44042LOW3.7UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the Base64 decode helper used for HTTP Basic authentic...
CVE-2026-44041MEDIUM6.5UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-string to multibyte conversion helper. In rfb/dh.cpp...
CVE-2026-44040MEDIUM6.5UltraVNC through 1.8.2.2 uses a cryptographically weak pseudo-random number generator to produce VNC authentication chal...
CVE-2026-2387MEDIUM6.4The Event Organiser plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi...