CVE Vulnerability Database

Search and browse 380,959 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-16289MEDIUM4.3The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending me...
CVE-2026-16276LOW2.7The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns...
CVE-2026-16274LOW2.7The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action...
CVE-2026-16250CRITICAL9.8The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an un...
CVE-2026-16060CRITICAL9.8The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the conten...
CVE-2026-16057MEDIUM6.5The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its...
CVE-2026-15931MEDIUM6.1The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthent...
CVE-2026-15930CRITICAL9.4The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration bef...
CVE-2026-15383MEDIUM6.1The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, whic...
CVE-2026-15260MEDIUM4.3The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in...
CVE-2026-15254MEDIUM6.5The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrat...
CVE-2026-15231LOW2.7The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to acc...
CVE-2026-14557CRITICAL9.1The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token i...
CVE-2026-13340MEDIUM6.1The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz ext...
CVE-2026-12965CRITICAL9.1The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action befo...
CVE-2026-12872CRITICAL9.8The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload ...
CVE-2025-15673MEDIUM4.9The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an...
CVE-2025-15672HIGH8.1The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserializa...
CVE-2026-6695MEDIUM5.5A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (...
CVE-2026-6694MEDIUM5.5A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable...
CVE-2026-18585MEDIUM5.3A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 a...
CVE-2026-18584MEDIUM5.4A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact...
CVE-2026-18583MEDIUM5.5A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc...
CVE-2026-14682HIGH8.7In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This i...
CVE-2026-13586MEDIUM5.3In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also a...