CVE Vulnerability Database

Search and browse 394,832 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-39490HIGH7.5Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.
CVE-2026-39437HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.
CVE-2026-2381MEDIUM6.5The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2026-10825HIGH7.1A denial-of-service vulnerability exists in the WebSocket API due to insufficient validation and handling of JSON-based ...
CVE-2025-68045HIGH7.5Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.
CVE-2026-8444HIGH8.8The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpf...
CVE-2026-46331HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/sched: fix pedit partial COW leading to page ca...
CVE-2026-10093MEDIUM6.4The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2025-9912MEDIUM6.3Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerabilit...
CVE-2026-9187MEDIUM5.3The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up t...
CVE-2026-8443HIGH8.8The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameter...
CVE-2026-6933HIGH8.8The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in version...
CVE-2026-5149MEDIUM6.5The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi...
CVE-2026-50255MEDIUM6.7Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne...
CVE-2026-10780MEDIUM4.3The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
CVE-2026-10635MEDIUM6.3On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain...
CVE-2025-10262MEDIUM6.3Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu...
CVE-2026-6964MEDIUM5.3The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i...
CVE-2026-7273HIGH8.8A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABT...
CVE-2026-42014MEDIUM6.6A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can ...
CVE-2026-1767HIGH8.1A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` compo...
CVE-2026-1766MEDIUM6.1A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracke...
CVE-2026-1765MEDIUM5.6A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This ...
CVE-2026-1764MEDIUM5.6A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially craf...
CVE-2026-12162MEDIUM5.5Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an ...