CVE Vulnerability Database
Search and browse 376,601 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16263 | HIGH | 8.8 | 0.3% | Aug 7, 2026 | The WP Maps WordPress plugin before 4.9.7 does not perform a capability check in one of its AJAX actions and does not p... |
| CVE-2026-16262 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating... |
| CVE-2026-16258 | CRITICAL | 9.8 | 0.2% | Aug 7, 2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u... |
| CVE-2026-16041 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p... |
| CVE-2026-16039 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, ... |
| CVE-2026-16038 | CRITICAL | 9.1 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or... |
| CVE-2026-16030 | HIGH | 8.1 | 0.1% | Aug 7, 2026 | The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t... |
| CVE-2026-15386 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att... |
| CVE-2026-15361 | HIGH | 8.1 | 0.2% | Aug 7, 2026 | The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n... |
| CVE-2026-15359 | MEDIUM | 6.5 | 0.1% | Aug 7, 2026 | The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow... |
| CVE-2026-15245 | MEDIUM | 5.4 | 0.2% | Aug 7, 2026 | The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con... |
| CVE-2026-15215 | HIGH | 8.8 | 0.2% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing ... |
| CVE-2026-15214 | MEDIUM | 4.3 | 0.1% | Aug 7, 2026 | The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription... |
| CVE-2026-15032 | MEDIUM | 6.1 | 0.2% | Aug 7, 2026 | The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an... |
| CVE-2026-14943 | HIGH | 7.5 | 0.1% | Aug 7, 2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d... |
| CVE-2026-14331 | MEDIUM | 6.1 | 0.2% | Aug 7, 2026 | The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a... |
| CVE-2026-14205 | CRITICAL | 9.8 | 0.1% | Aug 7, 2026 | The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid... |
| CVE-2026-49005 | LOW | 2.4 | 0.1% | Aug 7, 2026 | The root password hash of the device can be obtained through unencrypted information in the firmware. |
| CVE-2026-19195 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th... |
| CVE-2026-19193 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys... |
| CVE-2026-19192 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C... |
| CVE-2026-19191 | HIGH | 7.8 | 0.1% | Aug 7, 2026 | A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o... |
| CVE-2026-14365 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ... |
| CVE-2026-14364 | CRITICAL | 9.8 | 0.3% | Aug 7, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp... |
| CVE-2026-12801 | MEDIUM | 6.4 | 0.2% | Aug 7, 2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid... |
