CVE Vulnerability Database

Search and browse 381,176 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14920HIGH8.2## Summary
CVE-2026-14864MEDIUM5.4The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s...
CVE-2026-14841MEDIUM6.1The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before refle...
CVE-2026-14817MEDIUM6.8The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through cer...
CVE-2026-13389MEDIUM6.5The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST ...
CVE-2026-12586HIGH8.1The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset...
CVE-2026-11872MEDIUM4.3The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in ...
CVE-2025-15675MEDIUM4.8The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor...
CVE-2026-9335MEDIUM6.5A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp...
CVE-2026-8457CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and inc...
CVE-2026-18352HIGH7.5The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, ...
CVE-2026-13339HIGH7.5The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1...
CVE-2026-17002Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18556HIGH7.4Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass....
CVE-2026-55735HIGH7.5Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi...
CVE-2026-55734HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a...
CVE-2026-55733HIGH7.5Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c...
CVE-2026-54894HIGH7.5Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c...
CVE-2026-67355HIGH8.2guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain...
CVE-2026-67354HIGH8.2guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the...
CVE-2026-67353MEDIUM6.9guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit...
CVE-2026-67352HIGH7.6luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows ...
CVE-2026-67344HIGH8.5ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP...
CVE-2026-67343HIGH8.8ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing a...
CVE-2026-67342CRITICAL9.8ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, P...