CVE Vulnerability Database
Search and browse 394,301 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56051 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. |
| CVE-2026-56050 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access ... |
| CVE-2026-56049 | HIGH | 8.5 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. |
| CVE-2026-56042 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. |
| CVE-2026-56023 | MEDIUM | 5.4 | 0.2% | Jun 25, 2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. |
| CVE-2026-56014 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. |
| CVE-2026-56013 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. |
| CVE-2026-56006 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions. |
| CVE-2026-56005 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. |
| CVE-2026-54849 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. |
| CVE-2026-54848 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows R... |
| CVE-2026-54845 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. |
| CVE-2026-54844 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. |
| CVE-2026-54843 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. |
| CVE-2026-54842 | HIGH | 8.1 | 0.2% | Jun 25, 2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-54841 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. |
| CVE-2026-54838 | HIGH | 8.5 | 0.3% | Jun 25, 2026 | Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. |
| CVE-2026-54836 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ... |
| CVE-2026-54830 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. |
| CVE-2026-54829 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt... |
| CVE-2026-54828 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. |
| CVE-2026-54823 | CRITICAL | 9.9 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. |
| CVE-2026-54822 | HIGH | 8.5 | 0.3% | Jun 25, 2026 | Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. |
| CVE-2026-54821 | HIGH | 7.4 | 0.3% | Jun 25, 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. |
| CVE-2026-52690 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D... |
