CVE Vulnerability Database

Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-8040MEDIUM6.4The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute ...
CVE-2026-7614MEDIUM4.3The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2026-6268HIGH7.1The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_n...
CVE-2026-9236MEDIUM4.3The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cros...
CVE-2026-8450CRITICAL9.1HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string arg...
CVE-2026-6287MEDIUM5.4The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-49000HIGH7An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequa...
CVE-2025-14481MEDIUM4.3The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and includi...
CVE-2026-9022MEDIUM6.4The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in...
CVE-2026-48999MEDIUM5.7Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users a...
CVE-2026-48962HIGH7.3IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled ou...
CVE-2026-48961HIGH7.3IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine...
CVE-2026-48959HIGH7.5IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastFo...
CVE-2026-2255MEDIUM4.3Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, e...
CVE-2026-2254MEDIUM6.3Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, d...
CVE-2026-2253HIGH7.7Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, d...
CVE-2025-15649MEDIUM5.5IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed...
CVE-2026-9632HIGH8.8A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of th...
CVE-2026-9631HIGH8.8A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the functi...
CVE-2026-9628HIGH8.8A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /gofo...
CVE-2026-9627HIGH8.8A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file...
CVE-2026-9609MEDIUM4.7A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The ...
CVE-2026-9608LOW2.4A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /T...
CVE-2026-9207HIGH8.8Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-9156HIGH7.5Tanium addressed a denial of service vulnerability in Tanium Server.