CVE Vulnerability Database

Search and browse 376,624 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16258CRITICAL9.8The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing u...
CVE-2026-16041HIGH7.5The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST p...
CVE-2026-16039MEDIUM6.5The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, ...
CVE-2026-16038CRITICAL9.1The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an or...
CVE-2026-16030HIGH8.1The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used t...
CVE-2026-15386MEDIUM5.4The Meow Gallery WordPress plugin before 5.5.2 does not escape an attachment's alt text before outputting it into an att...
CVE-2026-15361HIGH8.1The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does n...
CVE-2026-15359MEDIUM6.5The Templately WordPress plugin before 3.7.1 does not have an authorisation check on one of its request handlers, allow...
CVE-2026-15245MEDIUM5.4The BNE Testimonials WordPress plugin before 2.0.8.2 does not properly escape a shortcode attribute for a JavaScript con...
CVE-2026-15215HIGH8.8The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify the user's capability before installing ...
CVE-2026-15214MEDIUM4.3The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not verify that the requester owns the subscription...
CVE-2026-15032MEDIUM6.1The Comments WordPress plugin before 7.6.60 does not properly escape a user-supplied URL before outputting it inside an...
CVE-2026-14943HIGH7.5The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 d...
CVE-2026-14331MEDIUM6.1The Subscribe2 WordPress plugin before 10.46 does not properly escape a user-supplied value before reflecting it into a...
CVE-2026-14205CRITICAL9.8The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid...
CVE-2026-49005LOW2.4The root password hash of the device can be obtained through unencrypted information in the firmware.
CVE-2026-19195HIGH7.8A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in th...
CVE-2026-19193HIGH7.8A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys...
CVE-2026-19192HIGH7.8A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C...
CVE-2026-19191HIGH7.8A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code o...
CVE-2026-14365CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in ...
CVE-2026-14364CRITICAL9.8The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via imp...
CVE-2026-12801MEDIUM6.4The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Range Slid...
CVE-2026-11907MEDIUM6.5The Stream plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.2.0. This ...
CVE-2026-19190HIGH7.8A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Fil...