CVE Vulnerability Database
Search and browse 380,666 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67554 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ... |
| CVE-2026-67553 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service... |
| CVE-2026-67552 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of... |
| CVE-2026-66277 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att... |
| CVE-2026-66276 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to ... |
| CVE-2026-66275 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service... |
| CVE-2026-66274 | HIGH | 7.5 | 0.4% | Aug 5, 2026 | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of... |
| CVE-2026-49004 | MEDIUM | 6.5 | 0.7% | Aug 5, 2026 | The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi... |
| CVE-2026-17515 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisatio... |
| CVE-2026-16993 | LOW | 3.7 | 0.1% | Aug 5, 2026 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc... |
| CVE-2026-16981 | MEDIUM | 5.3 | 0.1% | Aug 5, 2026 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa... |
| CVE-2026-16968 | MEDIUM | 6.5 | 0.1% | Aug 5, 2026 | The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users... |
| CVE-2026-16942 | MEDIUM | 5.4 | 0.2% | Aug 5, 2026 | The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand... |
| CVE-2026-16940 | CRITICAL | 10 | 0.2% | Aug 5, 2026 | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing un... |
| CVE-2026-16746 | LOW | 2.7 | 0.1% | Aug 5, 2026 | The MultiVendorX WordPress plugin before 5.0.11 does not verify that the requested store belongs to the current user in... |
| CVE-2026-16736 | HIGH | 7.5 | 0.1% | Aug 5, 2026 | The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled sett... |
| CVE-2026-16613 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable... |
| CVE-2026-16605 | HIGH | 7.2 | 0.1% | Aug 5, 2026 | The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to... |
| CVE-2026-16604 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before ... |
| CVE-2026-16603 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST... |
| CVE-2026-16602 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an u... |
| CVE-2026-16583 | MEDIUM | 6.1 | 0.2% | Aug 5, 2026 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8... |
| CVE-2026-16573 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing un... |
| CVE-2026-16561 | HIGH | 7.5 | 0.1% | Aug 5, 2026 | The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX action... |
| CVE-2026-16055 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress au... |
