CVE Vulnerability Database

Search and browse 377,740 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15360CRITICAL9.1The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a...
CVE-2026-15230HIGH8.1The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, rely...
CVE-2026-15210CRITICAL9.1The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verifi...
CVE-2026-14553HIGH8.1The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied conte...
CVE-2025-15677LOW3.5The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputtin...
CVE-2026-9273CRITICAL9.3The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password r...
CVE-2026-8790MEDIUM6.1The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST paramete...
CVE-2026-8761HIGH8.8The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This i...
CVE-2026-7753MEDIUM6.5The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing...
CVE-2026-71192MEDIUM6In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-C...
CVE-2026-71191MEDIUM6In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the Si...
CVE-2026-71190HIGH8.7In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to cat...
CVE-2026-68074HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-68060HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-67589HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-67588HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-67551HIGH7.5pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential d...
CVE-2026-67465HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-66839HIGH8.4NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerabil...
CVE-2026-66344MEDIUM6.7NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerabi...
CVE-2026-66273HIGH7.5A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential...
CVE-2026-66257HIGH7.5A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to deni...
CVE-2026-5062MEDIUM4.9The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre...
CVE-2026-55707HIGH7.1In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An au...
CVE-2026-18903MEDIUM4.3A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects so...