CVE Vulnerability Database

Search and browse 377,736 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-66274HIGH7.5A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of...
CVE-2026-49004MEDIUM6.5The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi...
CVE-2026-17515MEDIUM4.3The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio...
CVE-2026-16993LOW3.7The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc...
CVE-2026-16981MEDIUM5.3The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa...
CVE-2026-16968MEDIUM6.5The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users...
CVE-2026-16942MEDIUM5.4The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand...
CVE-2026-16940CRITICAL10The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing un...
CVE-2026-16746LOW2.7The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in...
CVE-2026-16736HIGH7.5The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled sett...
CVE-2026-16613MEDIUM4.3The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable...
CVE-2026-16605HIGH7.2The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to...
CVE-2026-16604HIGH7.5The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before ...
CVE-2026-16603HIGH7.5The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST...
CVE-2026-16602HIGH7.5The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an u...
CVE-2026-16583MEDIUM6.1The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8...
CVE-2026-16573HIGH7.5The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing un...
CVE-2026-16561HIGH7.5The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action...
CVE-2026-16055HIGH7.5The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au...
CVE-2026-16036HIGH7.5The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login ...
CVE-2026-15372HIGH7.5The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported m...
CVE-2026-15360CRITICAL9.1The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a...
CVE-2026-15230HIGH8.1The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, rely...
CVE-2026-15210CRITICAL9.1The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verifi...
CVE-2026-14553HIGH8.1The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied conte...