CVE Vulnerability Database

Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8907MEDIUM6.1The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1...
CVE-2026-8904MEDIUM4.3The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu...
CVE-2026-8902MEDIUM4.3The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2026-8895MEDIUM6.4The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod...
CVE-2026-8883MEDIUM6.4The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmical...
CVE-2026-8882MEDIUM6.4The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attri...
CVE-2026-8880MEDIUM6.4The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (a...
CVE-2026-8841MEDIUM6.4The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat'...
CVE-2026-8499MEDIUM5.3The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver...
CVE-2026-7662MEDIUM6.4The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attri...
CVE-2026-41980MEDIUM5.5Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a...
CVE-2026-41979MEDIUM5.5Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect i...
CVE-2026-41978MEDIUM4.4Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect s...
CVE-2026-41975MEDIUM6.3Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerabil...
CVE-2026-41855CRITICAL9.8In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin...
CVE-2026-41854MEDIUM6.5Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid...
CVE-2026-41853MEDIUM5.3Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr...
CVE-2026-41852MEDIUM5.3A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati...
CVE-2026-41851HIGH7.5Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S...
CVE-2026-41850HIGH7.5Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic ...
CVE-2026-41849HIGH7.5An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c...
CVE-2026-41848HIGH7.5Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid...
CVE-2026-41847MEDIUM5.3Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:...
CVE-2026-41846MEDIUM6.1Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP ...
CVE-2026-41845MEDIUM6.1Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br...