CVE Vulnerability Database

Search and browse 394,758 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-55706HIGH8.3sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f...
CVE-2026-54811CRITICAL9.3Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
CVE-2026-54807CRITICAL9.8Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
CVE-2026-54806CRITICAL9.8Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
CVE-2026-54805HIGH8.8Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions.
CVE-2026-54804HIGH7.6Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions.
CVE-2026-54803CRITICAL9.8Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.
CVE-2026-54802HIGH7.5Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions.
CVE-2026-54196MEDIUM6.8Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affe...
CVE-2026-54195HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
CVE-2026-54194CRITICAL9.8Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
CVE-2026-54192HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
CVE-2026-54189HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54188HIGH7.1Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
CVE-2026-54187CRITICAL9.3Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
CVE-2026-54186CRITICAL9.3Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.
CVE-2026-54185HIGH8.5Subscriber SQL Injection in Cornerstone < 7.8.8 versions.
CVE-2026-54184HIGH8.2Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
CVE-2026-53876HIGH8.6RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary c...
CVE-2026-52706CRITICAL9.8Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
CVE-2026-52705CRITICAL9Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
CVE-2026-52698HIGH7.4Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2...
CVE-2026-52696HIGH7.5Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions.
CVE-2026-50203CRITICAL9.1A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or...
CVE-2026-49778HIGH7.1Unauthenticated Cross Site Scripting (XSS) in WPFunnels Pro <= 2.9.4 versions.