CVE Vulnerability Database

Search and browse 394,378 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-12417CRITICAL9.8The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi...
CVE-2026-12416CRITICAL9.8The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a...
CVE-2026-12100HIGH7.2The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-12095HIGH7.2The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-12094MEDIUM5.3The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi...
CVE-2026-11997MEDIUM4.3The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1....
CVE-2026-11370MEDIUM6.4The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ...
CVE-2026-10753LOW2.7The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administ...
CVE-2026-10749HIGH7.2The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, stor...
CVE-2026-10735HIGH7.5Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, P...
CVE-2026-10552MEDIUM4.3The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1....
CVE-2026-10531MEDIUM5.4The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes bef...
CVE-2026-10092HIGH7.2The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc...
CVE-2026-10091HIGH7.2The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh...
CVE-2026-9539MEDIUM6.5An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp...
CVE-2026-12851CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12850CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12849CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12848CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12847CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12846CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-12488MEDIUM6.2A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2.  A specially cr...
CVE-2026-12486CRITICAL9.1Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09...
CVE-2026-12485CRITICAL10GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48...
CVE-2026-3652HIGH7.2The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save...