CVE Vulnerability Database
Search and browse 393,242 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14181 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when... |
| CVE-2026-13323 | HIGH | 8.7 | 0.2% | Jul 1, 2026 | In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/h... |
| CVE-2026-14258 | MEDIUM | 6.5 | 0.3% | Jul 1, 2026 | A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Ad... |
| CVE-2026-13228 | HIGH | 8.8 | — | Jul 1, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca... |
| CVE-2026-12142 | HIGH | 7.2 | — | Jul 1, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2026-10095 | MEDIUM | 6.4 | — | Jul 1, 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in... |
| CVE-2026-27435 | MEDIUM | 5.3 | 0.2% | Jul 1, 2026 | Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Securit... |
| CVE-2026-13454 | MEDIUM | 6.5 | 0.4% | Jul 1, 2026 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in a... |
| CVE-2026-12754 | MEDIUM | 6.1 | 0.3% | Jul 1, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '... |
| CVE-2026-56016 | MEDIUM | 5.9 | 0.3% | Jul 1, 2026 | CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The gene... |
| CVE-2026-50043 | HIGH | 8.6 | 1.1% | Jul 1, 2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-... |
| CVE-2026-13733 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attri... |
| CVE-2026-12732 | MEDIUM | 6.4 | 0.2% | Jul 1, 2026 | The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode ... |
| CVE-2026-12577 | HIGH | 8.7 | 0.3% | Jul 1, 2026 | DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability. |
| CVE-2026-12576 | HIGH | 7.5 | 0.2% | Jul 1, 2026 | DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability. |
| CVE-2026-12575 | HIGH | 7.5 | 0.3% | Jul 1, 2026 | DVP80ES3 with Improper Resource Shutdown or Release vulnerability. |
| CVE-2026-12435 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in a... |
| CVE-2026-12408 | MEDIUM | 4.3 | 0.3% | Jul 1, 2026 | The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Co... |
| CVE-2026-12224 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all ve... |
| CVE-2026-12158 | HIGH | 8.8 | 0.2% | Jul 1, 2026 | The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery ... |
| CVE-2026-11387 | CRITICAL | 9.8 | 0.4% | Jul 1, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
| CVE-2026-10540 | MEDIUM | 5.6 | 0.1% | Jul 1, 2026 | The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offl... |
| CVE-2026-10539 | CRITICAL | 9.5 | 0.2% | Jul 1, 2026 | A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain con... |
| CVE-2026-10538 | HIGH | 8.9 | 0.2% | Jul 1, 2026 | Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowe... |
| CVE-2026-10096 | MEDIUM | 4.3 | 0.2% | Jul 1, 2026 | The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includin... |
