CVE Vulnerability Database
Search and browse 376,700 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19054 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affec... |
| CVE-2026-18487 | MEDIUM | 5.4 | 0.3% | Aug 6, 2026 | A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name s... |
| CVE-2026-18367 | CRITICAL | 9.3 | 0.1% | Aug 6, 2026 | A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS ... |
| CVE-2026-17032 | CRITICAL | 9.8 | 0.4% | Aug 6, 2026 | Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allo... |
| CVE-2026-16620 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist f... |
| CVE-2026-16619 | HIGH | 7.5 | 0.2% | Aug 6, 2026 | The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attem... |
| CVE-2026-16067 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the ... |
| CVE-2026-15734 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated att... |
| CVE-2026-15733 | CRITICAL | 9.8 | 1.5% | Aug 6, 2026 | A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injectio... |
| CVE-2026-15732 | CRITICAL | 9.8 | 0.2% | Aug 6, 2026 | A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functiona... |
| CVE-2026-15256 | MEDIUM | 4.8 | 0.2% | Aug 6, 2026 | The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate ... |
| CVE-2026-15208 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p... |
| CVE-2026-15152 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment ... |
| CVE-2026-15149 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar... |
| CVE-2026-15147 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen... |
| CVE-2026-14936 | MEDIUM | 5.3 | 0.2% | Aug 6, 2026 | The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s... |
| CVE-2026-14842 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b... |
| CVE-2026-14831 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat... |
| CVE-2026-14812 | CRITICAL | 10 | 0.6% | Aug 6, 2026 | The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator ... |
| CVE-2026-14306 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected co... |
| CVE-2026-14225 | LOW | 2.7 | 0.2% | Aug 6, 2026 | The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-re... |
| CVE-2026-13399 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a... |
| CVE-2026-13342 | MEDIUM | 5.3 | 0.3% | Aug 6, 2026 | The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base... |
| CVE-2026-12901 | MEDIUM | 5.9 | 0.1% | Aug 6, 2026 | The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, ... |
| CVE-2026-12584 | HIGH | 7.5 | 0.2% | Aug 6, 2026 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of inco... |
