CVE Vulnerability Database

Search and browse 377,736 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-17505MEDIUM6.1The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting v...
CVE-2026-15281MEDIUM6.5The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w...
CVE-2026-12000HIGH7.5The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and...
CVE-2026-11977MEDIUM6.5The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to ...
CVE-2026-11969MEDIUM4.9The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete...
CVE-2026-11920MEDIUM4.9The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL ...
CVE-2026-11454MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object...
CVE-2026-71201MEDIUM5In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assign...
CVE-2026-70375HIGH8.8HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDe...
CVE-2026-70374HIGH8.8HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail genera...
CVE-2026-68080MEDIUM6.5It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta...
CVE-2026-68078MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-68077MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-68075MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-68073HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-67592HIGH7.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-67591MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-67590HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-67555MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-67554MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-67553MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...
CVE-2026-67552HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-66277MEDIUM6.5It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att...
CVE-2026-66276MEDIUM6.5An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ...
CVE-2026-66275MEDIUM6.5An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service...