CVE Vulnerability Database

Search and browse 394,735 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6798MEDIUM5.3The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version...
CVE-2026-46461HIGH7.8Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileg...
CVE-2026-3640MEDIUM5.3The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and ...
CVE-2026-9822MEDIUM6.5The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, a...
CVE-2026-9013MEDIUM4.3The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9....
CVE-2026-8713CRITICAL9.1The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v...
CVE-2026-8118MEDIUM6.5The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary ...
CVE-2026-7547MEDIUM4.9The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in ...
CVE-2026-7515CRITICAL9.8The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 vi...
CVE-2026-56132MEDIUM6.9In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array...
CVE-2026-56131MEDIUM4.9libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a...
CVE-2026-54414CRITICAL9.8FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedF...
CVE-2026-4328MEDIUM6.4The Advanced Import plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includi...
CVE-2026-1856MEDIUM6.4The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking fi...
CVE-2026-12644MEDIUM5.5Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of b...
CVE-2026-12430MEDIUM4.4The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio...
CVE-2026-12157MEDIUM6.4The BetterDocs - Knowledge Base Docs & FAQ Solution for Elementor & Block Editor plugin for WordPress is vulnerable to S...
CVE-2026-11989MEDIUM6.5The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vuln...
CVE-2026-11752MEDIUM5.9A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS mod...
CVE-2026-10779MEDIUM4.3The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization...
CVE-2026-10720MEDIUM5.1Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-im...
CVE-2026-10034MEDIUM5.3The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includin...
CVE-2025-7737HIGH8.6DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor...
CVE-2026-8806HIGH8.7Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET...
CVE-2026-8805HIGH8.7Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-E...