CVE Vulnerability Database

Search and browse 377,680 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-65544HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Super Socializer <= 7.14.5 versions.
CVE-2026-65543HIGH7.5Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
CVE-2026-65542HIGH8.8Unauthenticated Broken Authentication in Super Socializer <= 7.14.5 versions.
CVE-2026-65541HIGH7.3Unauthenticated Broken Access Control in Staff Training <= 1.0.7 versions.
CVE-2026-65523HIGH7.5Unauthenticated Insecure Direct Object References (IDOR) in Formidable Forms Signature Online Contract Automation <= 2.0...
CVE-2026-65520CRITICAL9.3Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.
CVE-2026-65517HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Easy PayPal Buy Now Button <= 2.0.4 versions.
CVE-2026-65515HIGH7.1Unauthenticated Cross Site Scripting (XSS) in AffiliateWP <= 2.35.0 versions.
CVE-2026-65513HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65509HIGH7.1Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions.
CVE-2026-65508CRITICAL9.3Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
CVE-2026-65507CRITICAL9.8Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
CVE-2026-65504HIGH7.5Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
CVE-2026-65502MEDIUM5.3Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
CVE-2026-61982HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
CVE-2026-61964HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.
CVE-2026-61963HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.
CVE-2026-61961HIGH7.1Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
CVE-2026-61959MEDIUM6.5Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.
CVE-2026-54489CRITICAL9.8Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Informati...
CVE-2026-53976CRITICAL9.3OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and...
CVE-2026-53975CRITICAL9.8OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execu...
CVE-2026-34502HIGH7.5Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache ...
CVE-2026-34501HIGH7.5Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por...
CVE-2026-34191CRITICAL9.1Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru...