CVE Vulnerability Database

Search and browse 397,925 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-6397MEDIUM6.4The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmorete...
CVE-2026-6395MEDIUM6.1The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting ...
CVE-2026-6394MEDIUM5.4The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server...
CVE-2026-6391MEDIUM6.1The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-6072MEDIUM6.5The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through Us...
CVE-2026-5293MEDIUM6.4The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js'...
CVE-2026-45232LOW3.7Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connect...
CVE-2026-43620MEDIUM5.5Rsync version 3.4.2 and prior contain a receiver-side out-of-bounds array read vulnerability in recv_files() in receiver...
CVE-2026-43619HIGH7.2Rsync version 3.4.2 and prior contain symlink race condition vulnerabilities in path-based system calls including chmod,...
CVE-2026-43618HIGH8.1Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit s...
CVE-2026-43617MEDIUM6.3Rsync version 3.4.2 and prior contain an authorization bypass vulnerability in the rsync daemon's hostname-based access ...
CVE-2026-3985HIGH7.5The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection v...
CVE-2026-45585MEDIUM6.8Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". ...
CVE-2026-39309MEDIUM5.5Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-35593MEDIUM6.8Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowled...
CVE-2026-34970MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to acces...
CVE-2026-34754MEDIUM4.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to ...
CVE-2026-8495CRITICAL9.8Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing. This issue affects Date iCal: from 0....
CVE-2026-8493MEDIUM5.4Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox In...
CVE-2026-8492LOW2.7Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource L...
CVE-2026-8491LOW3.7Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Brows...
CVE-2026-6871MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Obfuscate a...
CVE-2026-6367MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...
CVE-2026-6366MEDIUM6.6Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allow...
CVE-2026-6365MEDIUM6.1Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core...