CVE Vulnerability Database

Search and browse 395,821 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-3018HIGH7.5The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in ...
CVE-2026-11853MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages...
CVE-2026-11852MEDIUM6.5Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus...
CVE-2025-6254CRITICAL9.8The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8...
CVE-2026-9019MEDIUM6.4The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol...
CVE-2026-8853MEDIUM4.4The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version...
CVE-2026-8613MEDIUM6.4The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge...
CVE-2026-10721HIGH8.4Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the  in Permission, Cache, and...
CVE-2026-9067CRITICAL9.1The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ...
CVE-2026-9060LOW3.5The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o...
CVE-2026-8071HIGH8.8The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus...
CVE-2026-3326HIGH8.6The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state...
CVE-2026-29116HIGH8.7A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially...
CVE-2026-29115MEDIUM6.9A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c...
CVE-2026-29114LOW2.3A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ...
CVE-2026-11815MEDIUM5.3An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote...
CVE-2026-10846HIGH7.5NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks m...
CVE-2026-26241CRITICAL9.1A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu...
CVE-2026-26240CRITICAL9.1A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu...
CVE-2026-11837HIGH7.3A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() ...
CVE-2025-8444MEDIUM6.4The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerabl...
CVE-2026-26239HIGH8.1A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t...
CVE-2026-26237HIGH7.5A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul...
CVE-2026-24724HIGH8.1An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a...
CVE-2026-24720MEDIUM6.5An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r...