CVE Vulnerability Database
Search and browse 397,864 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8040 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute ... |
| CVE-2026-7614 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The Old Posts Highlighter plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2026-6268 | HIGH | 7.1 | 0.2% | May 27, 2026 | The EventPress WordPress theme before 22.2 does not sanitize or escape the 'id' parameter in the eventpress_customizer_n... |
| CVE-2026-9236 | MEDIUM | 4.3 | 0.1% | May 27, 2026 | The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cros... |
| CVE-2026-8450 | CRITICAL | 9.1 | 1.5% | May 27, 2026 | HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file(). send_file() opens its string arg... |
| CVE-2026-6287 | MEDIUM | 5.4 | 0.2% | May 27, 2026 | The ShopLentor - WooCommerce Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-49000 | HIGH | 7 | 0.1% | May 27, 2026 | An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequa... |
| CVE-2025-14481 | MEDIUM | 4.3 | 0.3% | May 27, 2026 | The Yoast SEO plugin for WordPress is vulnerable to Insecure Direct Object References in all versions up to, and includi... |
| CVE-2026-9022 | MEDIUM | 6.4 | 0.2% | May 27, 2026 | The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in... |
| CVE-2026-48999 | MEDIUM | 5.7 | 0.2% | May 27, 2026 | Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users a... |
| CVE-2026-48962 | HIGH | 7.3 | 0.3% | May 27, 2026 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled ou... |
| CVE-2026-48961 | HIGH | 7.3 | 0.3% | May 27, 2026 | IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine... |
| CVE-2026-48959 | HIGH | 7.5 | 0.4% | May 27, 2026 | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastFo... |
| CVE-2026-2255 | MEDIUM | 4.3 | 0.2% | May 27, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, e... |
| CVE-2026-2254 | MEDIUM | 6.3 | 0.2% | May 27, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, d... |
| CVE-2026-2253 | HIGH | 7.7 | 0.2% | May 27, 2026 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, d... |
| CVE-2025-15649 | MEDIUM | 5.5 | 0.1% | May 27, 2026 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed... |
| CVE-2026-9632 | HIGH | 8.8 | 0.5% | May 27, 2026 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of th... |
| CVE-2026-9631 | HIGH | 8.8 | 0.4% | May 27, 2026 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the functi... |
| CVE-2026-9628 | HIGH | 8.8 | 0.5% | May 27, 2026 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /gofo... |
| CVE-2026-9627 | HIGH | 8.8 | 0.5% | May 27, 2026 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file... |
| CVE-2026-9609 | MEDIUM | 4.7 | 0.2% | May 27, 2026 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The ... |
| CVE-2026-9608 | LOW | 2.4 | 0.2% | May 27, 2026 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /T... |
| CVE-2026-9207 | HIGH | 8.8 | 0.4% | May 27, 2026 | Tanium addressed an unauthorized code execution vulnerability in Connect. |
| CVE-2026-9156 | HIGH | 7.5 | 0.2% | May 27, 2026 | Tanium addressed a denial of service vulnerability in Tanium Server. |
