CVE Vulnerability Database
Search and browse 394,250 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54824 | HIGH | 7.5 | — | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions. |
| CVE-2026-54820 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. |
| CVE-2026-52701 | MEDIUM | 6.5 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions. |
| CVE-2026-4339 | MEDIUM | 6.5 | 0.1% | Jun 26, 2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against int... |
| CVE-2026-45257 | HIGH | 7.8 | — | Jun 26, 2026 | The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and s... |
| CVE-2026-45256 | MEDIUM | 5.5 | — | Jun 26, 2026 | When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation... |
| CVE-2026-3472 | LOW | 3.5 | 0.2% | Jun 26, 2026 | Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image render... |
| CVE-2026-30041 | HIGH | 7.5 | — | Jun 26, 2026 | An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code... |
| CVE-2026-30040 | MEDIUM | 6.5 | — | Jun 26, 2026 | A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary... |
| CVE-2026-24547 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. |
| CVE-2025-68075 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions. |
| CVE-2025-68074 | MEDIUM | 6.5 | — | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions. |
| CVE-2025-68064 | HIGH | 7.5 | — | Jun 26, 2026 | Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. |
| CVE-2025-68063 | HIGH | 7.5 | — | Jun 26, 2026 | Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versio... |
| CVE-2025-68052 | HIGH | 8.8 | — | Jun 26, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. |
| CVE-2025-66123 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions. |
| CVE-2025-64637 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | Unauthenticated Content Injection in Auros Core <= 5.3.1 versions. |
| CVE-2025-64636 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions. |
| CVE-2025-63079 | MEDIUM | 4.3 | — | Jun 26, 2026 | Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions. |
| CVE-2025-63078 | MEDIUM | 4.3 | — | Jun 26, 2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. |
| CVE-2025-63041 | MEDIUM | 5.4 | — | Jun 26, 2026 | Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions. |
| CVE-2026-57940 | LOW | 2.1 | — | Jun 26, 2026 | HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi... |
| CVE-2026-57926 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
| CVE-2026-57925 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags |
| CVE-2026-57924 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details |
