CVE Vulnerability Database

Search and browse 391,088 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13731HIGH7.2The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-13468HIGH7.5The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization ...
CVE-2026-13443MEDIUM6.4The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2026-13246MEDIUM6.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2026-13015MEDIUM6.1The Wp Google Places Review Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'place' ...
CVE-2026-12923HIGH7.5The Youtube Showcase plugin for WordPress is vulnerable to Arbitrary Function Call in versions up to and including 4.0.3...
CVE-2026-12904MEDIUM4.3The Kadence Blocks – Gutenberg Blocks for Page Builder Features plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2026-12902MEDIUM4.3The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-12135MEDIUM6.4The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' ...
CVE-2026-12133MEDIUM4.3The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Missing Authori...
CVE-2026-12127MEDIUM5.3The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2026-12113MEDIUM4.3The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2026-12110MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene...
CVE-2026-12090MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to gene...
CVE-2026-11988MEDIUM6.5The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure ...
CVE-2026-11981MEDIUM4.3The GiveWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.15.3 Thi...
CVE-2026-11380MEDIUM6.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and inc...
CVE-2026-20463MEDIUM6.7In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation o...
CVE-2026-20462MEDIUM6.7In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o...
CVE-2026-20461MEDIUM5.3In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of ser...
CVE-2026-20460MEDIUM5.3In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informa...
CVE-2026-20459MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-20458HIGH7.5In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of p...
CVE-2026-20457MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-14191HIGH7.8An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeade...