CVE Vulnerability Database

Search and browse 377,681 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-5158MEDIUM6.4The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored C...
CVE-2026-57818HIGH8.1A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via c...
CVE-2026-19035HIGH7.3A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of ...
CVE-2026-11983MEDIUM5.3The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2025-9266MEDIUM4.3The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-15028HIGH7.2The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is ...
CVE-2026-66909CRITICAL9.8Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, wit...
CVE-2026-65432HIGH7.5Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. Ho...
CVE-2026-64958HIGH7.5An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF...
CVE-2026-57819HIGH7.5Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" co...
CVE-2026-57817HIGH8.1The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in th...
CVE-2026-54225HIGH7.5Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4....
CVE-2026-19034HIGH7.3A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_s...
CVE-2026-55980MEDIUM5.5A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leadin...
CVE-2026-55979MEDIUM5.2An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke Ca...
CVE-2026-55978HIGH8.4An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an ...
CVE-2026-64640MEDIUM6.5Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti...
CVE-2026-19022MEDIUM6.3A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the fi...
CVE-2026-64604In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update if...
CVE-2026-64603In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handle...
CVE-2026-64602In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before reque...
CVE-2026-64601HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant us...
CVE-2026-64599HIGH7.8In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_cry...
CVE-2026-64598HIGH8.8In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc()...
CVE-2026-64597CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay...