CVE Vulnerability Database
Search and browse 381,026 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71399 | HIGH | 8.8 | 0.3% | Aug 2, 2026 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize... |
| CVE-2026-12231 | MEDIUM | 6.4 | 0.3% | Aug 2, 2026 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_info... |
| CVE-2026-18573 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza... |
| CVE-2026-18572 | MEDIUM | 6.5 | 0.2% | Aug 2, 2026 | Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie... |
| CVE-2026-18571 | HIGH | 7.2 | 0.2% | Aug 2, 2026 | A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled.... |
| CVE-2026-18570 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen... |
| CVE-2026-16540 | HIGH | 7.5 | 0.2% | Aug 2, 2026 | The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operati... |
| CVE-2026-16292 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta... |
| CVE-2026-16291 | MEDIUM | 4.3 | 0.1% | Aug 2, 2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user befo... |
| CVE-2026-16285 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before str... |
| CVE-2026-16273 | MEDIUM | 4.6 | 0.2% | Aug 2, 2026 | The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field ... |
| CVE-2026-16261 | HIGH | 7.5 | 0.2% | Aug 2, 2026 | The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the req... |
| CVE-2026-16256 | CRITICAL | 9.8 | 0.1% | Aug 2, 2026 | The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions av... |
| CVE-2026-16064 | MEDIUM | 5.4 | 0.1% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o... |
| CVE-2026-16063 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont... |
| CVE-2026-16062 | MEDIUM | 6.6 | 0.2% | Aug 2, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-co... |
| CVE-2026-16042 | MEDIUM | 4.3 | 0.1% | Aug 2, 2026 | The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowin... |
| CVE-2026-15939 | LOW | 2.7 | 0.1% | Aug 2, 2026 | The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST ... |
| CVE-2026-15385 | MEDIUM | 5.4 | 0.2% | Aug 2, 2026 | The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m... |
| CVE-2026-15248 | MEDIUM | 5.5 | 0.2% | Aug 2, 2026 | The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment ... |
| CVE-2026-15241 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one o... |
| CVE-2026-15236 | HIGH | 7.5 | 0.2% | Aug 2, 2026 | The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party... |
| CVE-2026-15206 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that w... |
| CVE-2026-15151 | HIGH | 7.5 | 0.1% | Aug 2, 2026 | The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its ... |
| CVE-2026-14938 | MEDIUM | 4.3 | 0.1% | Aug 2, 2026 | The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation be... |
