CVE Vulnerability Database
Search and browse 377,706 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-16537 | MEDIUM | 5.4 | — | Aug 6, 2026 | The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputtin... |
| CVE-2026-16290 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member... |
| CVE-2026-16268 | HIGH | 8.2 | 0.1% | Aug 6, 2026 | The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetchi... |
| CVE-2026-16065 | MEDIUM | 6.5 | — | Aug 6, 2026 | The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV fil... |
| CVE-2026-16054 | CRITICAL | 9.1 | 0.1% | Aug 6, 2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated us... |
| CVE-2026-14829 | HIGH | 8.2 | 0.1% | Aug 6, 2026 | The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not pr... |
| CVE-2026-14547 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t... |
| CVE-2026-14314 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel... |
| CVE-2026-14313 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-... |
| CVE-2026-14240 | MEDIUM | 5.3 | 0.1% | Aug 6, 2026 | The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub... |
| CVE-2026-14204 | MEDIUM | 6.5 | 0.1% | Aug 6, 2026 | The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, all... |
| CVE-2026-13703 | MEDIUM | 5.4 | 0.1% | Aug 6, 2026 | The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated... |
| CVE-2026-13154 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is pub... |
| CVE-2026-13153 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes ... |
| CVE-2026-12713 | CRITICAL | 9.1 | 0.2% | Aug 6, 2026 | The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using i... |
| CVE-2026-11588 | MEDIUM | 6.1 | — | Aug 6, 2026 | The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API route... |
| CVE-2025-15678 | MEDIUM | 6.1 | 0.2% | Aug 6, 2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any use... |
| CVE-2026-19000 | HIGH | 7.3 | 0.3% | Aug 6, 2026 | A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/... |
| CVE-2026-18998 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of ... |
| CVE-2026-18997 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBg... |
| CVE-2026-15459 | HIGH | 8.1 | 0.5% | Aug 6, 2026 | The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,... |
| CVE-2026-18996 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function P... |
| CVE-2026-18995 | MEDIUM | 4.3 | 0.3% | Aug 6, 2026 | A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the f... |
| CVE-2026-18993 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functiona... |
| CVE-2026-18992 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of ... |
