CVE Vulnerability Database
Search and browse 397,697 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8907 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1... |
| CVE-2026-8904 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vu... |
| CVE-2026-8902 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2026-8895 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcod... |
| CVE-2026-8883 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmical... |
| CVE-2026-8882 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attri... |
| CVE-2026-8880 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (a... |
| CVE-2026-8841 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat'... |
| CVE-2026-8499 | MEDIUM | 5.3 | 0.3% | Jun 9, 2026 | The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in ver... |
| CVE-2026-7662 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attri... |
| CVE-2026-41980 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may a... |
| CVE-2026-41979 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect i... |
| CVE-2026-41978 | MEDIUM | 4.4 | 0.1% | Jun 9, 2026 | Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2026-41975 | MEDIUM | 6.3 | 0.1% | Jun 9, 2026 | Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerabil... |
| CVE-2026-41855 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin... |
| CVE-2026-41854 | MEDIUM | 6.5 | 0.1% | Jun 9, 2026 | Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provid... |
| CVE-2026-41853 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Fr... |
| CVE-2026-41852 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocati... |
| CVE-2026-41851 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S... |
| CVE-2026-41850 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic ... |
| CVE-2026-41849 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c... |
| CVE-2026-41848 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid... |
| CVE-2026-41847 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions:... |
| CVE-2026-41846 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP ... |
| CVE-2026-41845 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the br... |
