CVE Vulnerability Database
Search and browse 394,851 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5079 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi... |
| CVE-2026-52704 | CRITICAL | 10 | 0.3% | Jun 15, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a... |
| CVE-2026-49111 | HIGH | 8.8 | 0.2% | Jun 15, 2026 | Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe... |
| CVE-2026-49064 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da... |
| CVE-2026-49062 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex... |
| CVE-2026-48969 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions. |
| CVE-2025-64215 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Missing Authorization vulnerability in StylemixThemes MasterStudy LMS Pro allows Accessing Functionality Not Properly Co... |
| CVE-2019-25746 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attacker... |
| CVE-2018-25437 | HIGH | 8.7 | 0.3% | Jun 15, 2026 | WordPress CherryFramework Themes 3.1.4 contains an information disclosure vulnerability that allows unauthenticated atta... |
| CVE-2018-25436 | CRITICAL | 9.8 | 0.7% | Jun 15, 2026 | WordPress Plugin Baggage Freight Shipping Australia 0.1.0 contains an unrestricted file upload vulnerability that allows... |
| CVE-2016-20084 | HIGH | 7.2 | 0.2% | Jun 15, 2026 | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthen... |
| CVE-2016-20083 | MEDIUM | 6.9 | 0.1% | Jun 15, 2026 | WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform un... |
| CVE-2016-20082 | MEDIUM | 6.9 | 0.3% | Jun 15, 2026 | WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include a... |
| CVE-2016-20081 | HIGH | 8.7 | 0.6% | Jun 15, 2026 | WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attacke... |
| CVE-2016-20080 | MEDIUM | 6.9 | 0.4% | Jun 15, 2026 | WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that ... |
| CVE-2016-20079 | MEDIUM | 6.9 | 0.8% | Jun 15, 2026 | WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated at... |
| CVE-2016-20078 | MEDIUM | 6.9 | 0.7% | Jun 15, 2026 | WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers ... |
| CVE-2016-20077 | MEDIUM | 6.9 | 0.4% | Jun 15, 2026 | WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers ... |
| CVE-2016-20076 | HIGH | 8.7 | 0.6% | Jun 15, 2026 | WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrar... |
| CVE-2016-20075 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users... |
| CVE-2016-20074 | MEDIUM | 5.3 | 0.1% | Jun 15, 2026 | WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to pe... |
| CVE-2016-20073 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attacker... |
| CVE-2016-20072 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers... |
| CVE-2016-20071 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability tha... |
| CVE-2016-20070 | MEDIUM | 6.4 | 0.2% | Jun 15, 2026 | WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabili... |
