CVE Vulnerability Database

Search and browse 398,037 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-5693MEDIUM5.3The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
CVE-2026-5340MEDIUM6.4The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show`...
CVE-2026-5028MEDIUM6.5The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' p...
CVE-2026-4920MEDIUM6.4The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in...
CVE-2026-4859MEDIUM6.4The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the...
CVE-2026-4663——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39608. Reason: This candidate is a ...
CVE-2026-4301MEDIUM4.3The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorizatio...
CVE-2026-3604MEDIUM4.9The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ativ...
CVE-2026-39432HIGH8.2Missing Authorization vulnerability in Arraytics Timetics allows Exploiting Incorrectly Configured Access Control Securi...
CVE-2026-2993HIGH7.5The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and ...
CVE-2026-2300MEDIUM6.4The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in...
CVE-2026-35227HIGH8.2An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a...
CVE-2026-1681MEDIUM6.1Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursi...
CVE-2026-1185HIGH8.8A configuration file on the local file system had improper input validation which could allow code execution and potenti...
CVE-2026-0804HIGH7.3An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote...
CVE-2026-0802HIGH7.3An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead ...
CVE-2026-0541HIGH7.3ACAP applications can gain elevated privileges due to improper input validation during the installation process, potenti...
CVE-2026-41872CRITICAL9.1"Kura Sushi Official App" provided by EPG, Inc. is vulnerable to improper certificate validation. A man-in-the-middle at...
CVE-2026-41530MEDIUM4.6The automatic folder creation feature of Lhaz and Lhaz+ provided by Chitora soft contains a path traversal vulnerability...
CVE-2026-7287HIGH7.5** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formU...
CVE-2026-7257MEDIUM4.4** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of ...
CVE-2026-7256HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware versio...
CVE-2026-7255MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web ma...
CVE-2026-45430HIGH7.1The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the au...
CVE-2026-40137MEDIUM6.1SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when ...