CVE Vulnerability Database
Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42744 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded... |
| CVE-2026-42740 | CRITICAL | 9.3 | 0.2% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan ... |
| CVE-2026-42739 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced I... |
| CVE-2026-42738 | HIGH | 7.1 | 0.1% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZAYTECH Smart Onli... |
| CVE-2026-42737 | HIGH | 8.6 | 0.3% | May 27, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hote... |
| CVE-2026-42736 | HIGH | 7.5 | 0.2% | May 27, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in wordplus BP Better Messages bp-better-messages allows ... |
| CVE-2026-42735 | HIGH | 8.2 | 0.3% | May 27, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-managem... |
| CVE-2026-42734 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Ma... |
| CVE-2026-42733 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in RealMag777 WPCS cu... |
| CVE-2026-42732 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded... |
| CVE-2026-42731 | CRITICAL | 9.8 | 0.3% | May 27, 2026 | Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allow... |
| CVE-2026-42730 | HIGH | 8.5 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStu... |
| CVE-2026-42729 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive Prop... |
| CVE-2026-42728 | HIGH | 7.1 | 0.2% | May 27, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Cont... |
| CVE-2026-42727 | CRITICAL | 9.3 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 Active ... |
| CVE-2026-42726 | MEDIUM | 6.5 | 0.2% | May 27, 2026 | Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Explo... |
| CVE-2026-42725 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout... |
| CVE-2026-3349 | MEDIUM | 6.1 | 0.3% | May 27, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter o... |
| CVE-2026-3348 | MEDIUM | 4.4 | 0.2% | May 27, 2026 | The MinhNhut Link Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings (D... |
| CVE-2026-3012 | MEDIUM | 6.8 | 0.2% | May 27, 2026 | A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabl... |
| CVE-2026-2288 | MEDIUM | 4.8 | 0.2% | May 27, 2026 | The myLinksDump plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_title' parameter in all ... |
| CVE-2026-2280 | MEDIUM | 4.8 | 0.2% | May 27, 2026 | The rexCrawler plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2025-0898 | MEDIUM | 6.5 | 0.3% | May 27, 2026 | The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and ... |
| CVE-2026-8054 | CRITICAL | 10 | 1.6% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints ... |
| CVE-2026-49002 | CRITICAL | 9.1 | 0.3% | May 27, 2026 | Access control failure means that an application does not effectively check user access permissions, so that unauthorize... |
