CVE Vulnerability Database

Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8832HIGH8.8The WPCode - Insert Headers and Footers + Custom Code Snippets - WordPress Code Manager plugin for WordPress is vulnerab...
CVE-2026-8143HIGH7.2The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso'...
CVE-2026-8042MEDIUM6.4The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribut...
CVE-2026-7618MEDIUM4.9The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection vi...
CVE-2026-6169HIGH7.2The affiliate-toolkit plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, ...
CVE-2026-49001MEDIUM5.3Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cro...
CVE-2026-41704MEDIUM6.8AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every re...
CVE-2026-41009MEDIUM5.8When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient...
CVE-2026-40826MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dsgvo_contracts view...
CVE-2026-40825HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view d...
CVE-2026-40824HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the accountstatus view u...
CVE-2026-40823HIGH7A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct...
CVE-2026-40822MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the DevSerialReset funct...
CVE-2026-40821MEDIUM6.9A high privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAccountByID funct...
CVE-2026-40819HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task du...
CVE-2026-40818HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevic...
CVE-2026-40817HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles fu...
CVE-2026-40816HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files...
CVE-2026-40815HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAcc...
CVE-2026-40814HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _...
CVE-2026-40813HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct...
CVE-2026-40812HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues funct...
CVE-2026-40811HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice ...
CVE-2026-40810HIGH8.7An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint d...
CVE-2026-3897MEDIUM6.4The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `labb_a...