CVE Vulnerability Database

Search and browse 397,888 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9104MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up...
CVE-2026-9018HIGH8.8The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation ...
CVE-2026-7509MEDIUM6.4The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` short...
CVE-2026-7249MEDIUM4.3The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability c...
CVE-2026-6864MEDIUM6.1The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' param...
CVE-2026-4070MEDIUM4.3The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-44409HIGH7.5There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control m...
CVE-2026-3481MEDIUM6.1The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in al...
CVE-2026-2518MEDIUM4.3The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing ca...
CVE-2026-9054CRITICAL9.2An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size would trigger a kernel p...
CVE-2026-9053MEDIUM6.9Mothra would respect a default value given by a website for HTML file upload forms. An attacker could craft a website wi...
CVE-2026-4834HIGH7.5The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to,...
CVE-2026-46598MEDIUM5.3For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when ...
CVE-2026-46597HIGH7.5An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafte...
CVE-2026-46595CRITICAL10Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of cal...
CVE-2026-42508CRITICAL9.1Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and...
CVE-2026-39835MEDIUM5.3SSH servers which use CertChecker as a public key callback without setting IsUserAuthority or IsHostAuthority could be c...
CVE-2026-39834CRITICAL9.1When writing data larger than 4GB in a single Write call on an SSH channel, an integer overflow in the internal payload ...
CVE-2026-39833CRITICAL9.1The in-memory keyring returned by NewKeyring() silently accepted keys with the ConfirmBeforeUse constraint but never enf...
CVE-2026-39832CRITICAL9.1When adding a key to a remote agent constraint extensions such as restrict-destination-v00@openssh.com were not serializ...
CVE-2026-39831CRITICAL9.1The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did...
CVE-2026-39830CRITICAL9.1A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection...
CVE-2026-39829HIGH7.5The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessive...
CVE-2026-39828MEDIUM6.3When an SSH server authentication callback returned PartialSuccessError with non-nil Permissions, those permissions were...
CVE-2026-39827MEDIUM6.5An authenticated SSH client that repeatedly opened channels which were rejected by the server caused unbounded memory gr...