CVE Vulnerability Database
Search and browse 394,378 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12417 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi... |
| CVE-2026-12416 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a... |
| CVE-2026-12100 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2026-12095 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2026-12094 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a mi... |
| CVE-2026-11997 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.... |
| CVE-2026-11370 | MEDIUM | 6.4 | 0.2% | Jun 24, 2026 | The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, ... |
| CVE-2026-10753 | LOW | 2.7 | 0.2% | Jun 24, 2026 | The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administ... |
| CVE-2026-10749 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, stor... |
| CVE-2026-10735 | HIGH | 7.5 | 0.4% | Jun 24, 2026 | Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, P... |
| CVE-2026-10552 | MEDIUM | 4.3 | 0.1% | Jun 24, 2026 | The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1.... |
| CVE-2026-10531 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes bef... |
| CVE-2026-10092 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc... |
| CVE-2026-10091 | HIGH | 7.2 | 0.3% | Jun 24, 2026 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh... |
| CVE-2026-9539 | MEDIUM | 6.5 | 0.1% | Jun 24, 2026 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp... |
| CVE-2026-12851 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12850 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12849 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12848 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-12847 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-12846 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-12488 | MEDIUM | 6.2 | 0.2% | Jun 24, 2026 | A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially cr... |
| CVE-2026-12486 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12485 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-3652 | HIGH | 7.2 | 0.2% | Jun 24, 2026 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save... |
