CVE Vulnerability Database
Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8832 | HIGH | 8.8 | 1.2% | May 27, 2026 | The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerab... |
| CVE-2026-8143 | HIGH | 7.2 | 0.2% | May 27, 2026 | The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso'... |
| CVE-2026-8042 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut... |
| CVE-2026-7618 | MEDIUM | 4.9 | 0.3% | May 27, 2026 | The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi... |
| CVE-2026-6169 | HIGH | 7.2 | 0.6% | May 27, 2026 | The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, ... |
| CVE-2026-49001 | MEDIUM | 5.3 | 0.1% | May 27, 2026 | Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro... |
| CVE-2026-41704 | MEDIUM | 6.8 | 0.1% | May 27, 2026 | AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re... |
| CVE-2026-41009 | MEDIUM | 5.8 | 0.1% | May 27, 2026 | When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient... |
| CVE-2026-40826 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view... |
| CVE-2026-40825 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d... |
| CVE-2026-40824 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u... |
| CVE-2026-40823 | HIGH | 7 | 0.2% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct... |
| CVE-2026-40822 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct... |
| CVE-2026-40821 | MEDIUM | 6.9 | 0.3% | May 27, 2026 | A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct... |
| CVE-2026-40819 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task du... |
| CVE-2026-40818 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevic... |
| CVE-2026-40817 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles fu... |
| CVE-2026-40816 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files... |
| CVE-2026-40815 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAcc... |
| CVE-2026-40814 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _... |
| CVE-2026-40813 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct... |
| CVE-2026-40812 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct... |
| CVE-2026-40811 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice ... |
| CVE-2026-40810 | HIGH | 8.7 | 0.3% | May 27, 2026 | An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint d... |
| CVE-2026-3897 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_a... |
