CVE Vulnerability Database

Search and browse 397,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-7051MEDIUM5.4The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Missing Authorization in all v...
CVE-2026-6962MEDIUM6.4The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-6828MEDIUM6.4The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2025-9989MEDIUM4.4The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2025-9988MEDIUM4.3The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the creat...
CVE-2025-9987MEDIUM5.3The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2025-14755MEDIUM5.3The Cost Calculator Builder plugin for WordPress is vulnerable to Unauthenticated Price Manipulation and Insecure Direct...
CVE-2026-8336MEDIUM6.5After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in...
CVE-2026-8202MEDIUM6.5Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $r...
CVE-2026-8201HIGH8.8A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie...
CVE-2026-8200MEDIUM5.3When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc...
CVE-2026-8199HIGH7.1An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny...
CVE-2026-8053HIGH8.8An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv...
CVE-2026-6888HIGH7.2Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitr...
CVE-2025-62627HIGH7.2An untrusted pointer dereference in the ionic cloud driver for VMWare ESXi could allow an attacker with an unprivileged ...
CVE-2025-62624HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-62623HIGH8.8A heap-based buffer overflow in the ionic cloud driver for VMware ESXi could allow an attacker to achieve privilege esca...
CVE-2025-61972HIGH8.5Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Ma...
CVE-2025-61971MEDIUM5.9Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing conf...
CVE-2024-36315MEDIUM5.7Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and poten...
CVE-2026-8108HIGH7.8The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.
CVE-2026-5371HIGH7.1The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnera...
CVE-2026-44548HIGH8.1ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attack...
CVE-2026-44547CRITICAL9.6ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The ...
CVE-2026-44352MEDIUM5.3Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...