CVE Vulnerability Database

Search and browse 375,498 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16538The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top...
CVE-2026-16294The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode...
CVE-2026-16253The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-resto...
CVE-2026-16066The Welcart e-Commerce WordPress plugin before 2.11.34 does not sanitise or escape a product field before outputting it ...
CVE-2026-16051The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its re...
CVE-2026-15388The Cookie Consent WordPress plugin before 0.0.10 does not correctly enforce its intended administrator-only capability...
CVE-2026-15249The Patterns Kit WordPress plugin through 1.0.3 does not escape a link attribute before its client-side script inserts i...
CVE-2026-15039The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, all...
CVE-2026-14925The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file downlo...
CVE-2026-14859The WP Crowdfunding WordPress plugin before 2.2.1 does not check the campaign-submission capability in one of its AJAX a...
CVE-2026-14858The WP Crowdfunding WordPress plugin before 2.2.1 does not verify order ownership before returning order details, allowi...
CVE-2026-14857The WP Crowdfunding WordPress plugin before 2.2.1 does not verify ownership of a campaign before allowing its update his...
CVE-2026-13613The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using ...
CVE-2026-13612The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, al...
CVE-2026-13177The Eventin WordPress plugin before 4.1.20 does not properly restrict access to individual order records, allowing user...
CVE-2026-13171The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration han...
CVE-2026-13168The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users...
CVE-2026-12976The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a...
CVE-2026-64954HIGH8.2Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, th...
CVE-2026-12235MEDIUM6.3The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/RELA relocation entries when linking a relocatable (p...
CVE-2026-12234HIGH7.8The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c sn...
CVE-2026-12233MEDIUM5.9The PSA Protected Storage credential backend (subsys/net/lib/tls_credentials/tls_credentials_trusted.c) declared its cre...
CVE-2026-12232MEDIUM6.1The Intel ALH digital-audio-interface driver function dai_alh_get_properties() in drivers/dai/intel/alh/alh.c used a cal...
CVE-2025-15687MEDIUM4.3A security flaw has been discovered in Open5GS up to 2.7.6. Impacted is the function smf_gx_cca_cb of the component SMF ...
CVE-2026-9318MEDIUM5.4tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows...