CVE Vulnerability Database

Search and browse 381,026 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-71399HIGH8.8Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize...
CVE-2026-12231MEDIUM6.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info...
CVE-2026-18573MEDIUM6.5A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza...
CVE-2026-18572MEDIUM6.5Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie...
CVE-2026-18571HIGH7.2A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled....
CVE-2026-18570MEDIUM5.4A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen...
CVE-2026-16540HIGH7.5The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati...
CVE-2026-16292MEDIUM5.4The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta...
CVE-2026-16291MEDIUM4.3The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo...
CVE-2026-16285HIGH7.5The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str...
CVE-2026-16273MEDIUM4.6The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field ...
CVE-2026-16261HIGH7.5The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req...
CVE-2026-16256CRITICAL9.8The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions av...
CVE-2026-16064MEDIUM5.4The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o...
CVE-2026-16063MEDIUM5.4The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont...
CVE-2026-16062MEDIUM6.6The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co...
CVE-2026-16042MEDIUM4.3The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin...
CVE-2026-15939LOW2.7The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ...
CVE-2026-15385MEDIUM5.4The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m...
CVE-2026-15248MEDIUM5.5The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment ...
CVE-2026-15241HIGH7.5The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o...
CVE-2026-15236HIGH7.5The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party...
CVE-2026-15206HIGH7.5The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w...
CVE-2026-15151HIGH7.5The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its ...
CVE-2026-14938MEDIUM4.3The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be...