CVE Vulnerability Database

Search and browse 380,204 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15452MEDIUM4.7The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2026-0931MEDIUM6.9Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cau...
CVE-2026-8029LOW3.9The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements ...
CVE-2026-10090CRITICAL9A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cl...
CVE-2026-10059CRITICAL9.1A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namesp...
CVE-2026-7726MEDIUM6.5The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on...
CVE-2026-7693HIGH7.2The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2....
CVE-2026-7520HIGH8.1The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2026-7444HIGH8.1The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2026-7441MEDIUM6.4The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute...
CVE-2026-7105MEDIUM4.3The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on...
CVE-2026-71215HIGH7.5art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and ext...
CVE-2026-71214CRITICAL9.8The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasur...
CVE-2026-71213CRITICAL9.1Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting,...
CVE-2026-71212MEDIUM4.4xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py...
CVE-2026-71211HIGH7.1MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _cr...
CVE-2026-71210MEDIUM5.3Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r...
CVE-2026-71209HIGH7.5audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes agai...
CVE-2026-71208MEDIUM6.5KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl...
CVE-2026-71207CRITICAL9.8The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its aut...
CVE-2026-71206HIGH8.3Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded...
CVE-2026-71205MEDIUM6.5changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP ...
CVE-2026-71204MEDIUM6.2changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into...
CVE-2026-71203MEDIUM5.3changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke...
CVE-2026-71202HIGH7.5The raster Rust crate's crop function (src/editor.rs) clamps the crop width/height against source dimensions but only cl...