CVE Vulnerability Database
Search and browse 377,722 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7444 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2026-7441 | MEDIUM | 6.4 | 0.2% | Aug 5, 2026 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute... |
| CVE-2026-7105 | MEDIUM | 4.3 | 0.2% | Aug 5, 2026 | The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on... |
| CVE-2026-71215 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and ext... |
| CVE-2026-71214 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasur... |
| CVE-2026-71213 | CRITICAL | 9.1 | 0.4% | Aug 5, 2026 | Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,... |
| CVE-2026-71212 | MEDIUM | 4.4 | 0.1% | Aug 5, 2026 | xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py... |
| CVE-2026-71211 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr... |
| CVE-2026-71210 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r... |
| CVE-2026-71209 | HIGH | 7.5 | 0.7% | Aug 5, 2026 | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes agai... |
| CVE-2026-71208 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl... |
| CVE-2026-71207 | CRITICAL | 9.8 | 0.7% | Aug 5, 2026 | The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its aut... |
| CVE-2026-71206 | HIGH | 8.3 | 0.2% | Aug 5, 2026 | Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded... |
| CVE-2026-71205 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP ... |
| CVE-2026-71204 | MEDIUM | 6.2 | 0.2% | Aug 5, 2026 | changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into... |
| CVE-2026-71203 | MEDIUM | 5.3 | 0.2% | Aug 5, 2026 | changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke... |
| CVE-2026-71202 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only cl... |
| CVE-2026-70378 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is posit... |
| CVE-2026-70377 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * rat... |
| CVE-2026-70376 | CRITICAL | 9.6 | 0.2% | Aug 5, 2026 | Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.adm... |
| CVE-2026-6972 | MEDIUM | 6.4 | 0.2% | Aug 5, 2026 | The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of th... |
| CVE-2026-6639 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all... |
| CVE-2026-6627 | HIGH | 8.2 | 0.6% | Aug 5, 2026 | The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification a... |
| CVE-2026-6147 | HIGH | 8.8 | 0.7% | Aug 5, 2026 | The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2026-6079 | HIGH | 7.3 | 0.4% | Aug 5, 2026 | The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing... |
