CVE Vulnerability Database
Search and browse 395,821 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-3018 | HIGH | 7.5 | 1.4% | Jun 10, 2026 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in ... |
| CVE-2026-11853 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages... |
| CVE-2026-11852 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus... |
| CVE-2025-6254 | CRITICAL | 9.8 | 0.5% | Jun 10, 2026 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8... |
| CVE-2026-9019 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol... |
| CVE-2026-8853 | MEDIUM | 4.4 | 0.2% | Jun 10, 2026 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version... |
| CVE-2026-8613 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge... |
| CVE-2026-10721 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and... |
| CVE-2026-9067 | CRITICAL | 9.1 | 0.4% | Jun 10, 2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ... |
| CVE-2026-9060 | LOW | 3.5 | 0.1% | Jun 10, 2026 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o... |
| CVE-2026-8071 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus... |
| CVE-2026-3326 | HIGH | 8.6 | 1.0% | Jun 10, 2026 | The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state... |
| CVE-2026-29116 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially... |
| CVE-2026-29115 | MEDIUM | 6.9 | 0.4% | Jun 10, 2026 | A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c... |
| CVE-2026-29114 | LOW | 2.3 | 0.2% | Jun 10, 2026 | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ... |
| CVE-2026-11815 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote... |
| CVE-2026-10846 | HIGH | 7.5 | 0.1% | Jun 10, 2026 | NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks m... |
| CVE-2026-26241 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu... |
| CVE-2026-26240 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu... |
| CVE-2026-11837 | HIGH | 7.3 | 0.2% | Jun 10, 2026 | A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() ... |
| CVE-2025-8444 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerabl... |
| CVE-2026-26239 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t... |
| CVE-2026-26237 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul... |
| CVE-2026-24724 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a... |
| CVE-2026-24720 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r... |
