CVE Vulnerability Database

Search and browse 394,857 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6428HIGH7.6SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x b...
CVE-2026-5513HIGH7.2The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-1291MEDIUM4.3The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2026-11624CRITICAL9.4The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne...
CVE-2026-9629MEDIUM6.4The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up ...
CVE-2026-3297MEDIUM6.4The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2026-2470MEDIUM4.3The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Incorrect Authorizatio...
CVE-2026-9134MEDIUM6.4The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcod...
CVE-2026-9109HIGH7.2The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vu...
CVE-2026-9062LOW3.4The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h...
CVE-2026-9061LOW3.5The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o...
CVE-2026-11769HIGH8.8We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t...
CVE-2026-9848HIGH7.5The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers...
CVE-2026-54231MEDIUM5.5A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script...
CVE-2026-54230HIGH7.8A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts wr...
CVE-2026-54229HIGH7A race condition was found in the abrt-dbus D-Bus service's ChownProblemDir method. ChownProblemDir opens the dump direc...
CVE-2026-54228HIGH7.8A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Betwee...
CVE-2026-12089MEDIUM4.9The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in v...
CVE-2026-11443MEDIUM4.6Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at...
CVE-2026-11442MEDIUM6.5Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacker...
CVE-2026-6676HIGH7.8Heap buffer out-of-bounds write vulnerability in Avira Antivirus engine when scanning a malformed POSIX tar archive may ...
CVE-2026-12068HIGH7.4Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacke...
CVE-2025-9033HIGH7.8Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed PDF file may allow Loca...
CVE-2025-9032HIGH7.8Heap buffer out-of-bounds read vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may all...
CVE-2025-14098HIGH7.8Heap buffer out-of-bounds write vulnerability due to integer overflow in Avira Antivirus engine when scanning a malforme...