CVE Vulnerability Database
Search and browse 378,072 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14557 | CRITICAL | 9.1 | 0.2% | Aug 3, 2026 | The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token i... |
| CVE-2026-13340 | MEDIUM | 6.1 | 0.2% | Aug 3, 2026 | The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz ext... |
| CVE-2026-12965 | CRITICAL | 9.1 | 0.2% | Aug 3, 2026 | The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befo... |
| CVE-2026-12872 | CRITICAL | 9.8 | 0.3% | Aug 3, 2026 | The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload ... |
| CVE-2025-15673 | MEDIUM | 4.9 | 0.2% | Aug 3, 2026 | The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an... |
| CVE-2025-15672 | HIGH | 8.1 | 0.2% | Aug 3, 2026 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa... |
| CVE-2026-6695 | MEDIUM | 5.5 | 0.2% | Aug 3, 2026 | A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (... |
| CVE-2026-6694 | MEDIUM | 5.5 | 0.1% | Aug 3, 2026 | A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable... |
| CVE-2026-18585 | MEDIUM | 5.3 | 0.3% | Aug 3, 2026 | A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 a... |
| CVE-2026-18584 | MEDIUM | 5.4 | 0.2% | Aug 3, 2026 | A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact... |
| CVE-2026-18583 | MEDIUM | 5.5 | 0.5% | Aug 3, 2026 | A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc... |
| CVE-2026-14682 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This i... |
| CVE-2026-13586 | MEDIUM | 5.3 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also a... |
| CVE-2026-13506 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects B... |
| CVE-2026-12860 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issu... |
| CVE-2026-12852 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check. |
| CVE-2026-12817 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also af... |
| CVE-2026-12816 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also... |
| CVE-2026-12803 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forg... |
| CVE-2026-12802 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also ... |
| CVE-2026-58063 | MEDIUM | 5.3 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue al... |
| CVE-2026-58062 | CRITICAL | 9.3 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This i... |
| CVE-2026-58061 | HIGH | 8.7 | 0.2% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue al... |
| CVE-2026-58060 | HIGH | 8.7 | 0.4% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This is... |
| CVE-2026-58059 | HIGH | 8.7 | 0.3% | Aug 3, 2026 | In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue a... |
