CVE Vulnerability Database

Search and browse 381,202 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18209MEDIUM4.7A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flow...
CVE-2026-18208MEDIUM6.5A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source...
CVE-2026-18206LOW3.7A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services....
CVE-2026-18203MEDIUM6.5A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr...
CVE-2026-16105MEDIUM4.9A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin...
CVE-2026-8155MEDIUM5.4The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints...
CVE-2026-18452CRITICAL10DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att...
CVE-2026-16236HIGH8.8The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5...
CVE-2026-15381LOW3.7The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S...
CVE-2026-15258HIGH8.1The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-fe...
CVE-2026-15209MEDIUM6.5The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a...
CVE-2026-15048HIGH7.5The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowin...
CVE-2026-14931MEDIUM6.5The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation ...
CVE-2026-14930HIGH7.5The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front...
CVE-2026-14929MEDIUM4.3The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allo...
CVE-2026-14928MEDIUM6.5The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp...
CVE-2026-14927LOW3.7The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che...
CVE-2026-14922MEDIUM6.1WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 throug...
CVE-2026-14921MEDIUM6.1The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_...
CVE-2026-14919CRITICAL9.8The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it be...
CVE-2026-14862LOW3.7The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo...
CVE-2026-14849LOW3.7The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it...
CVE-2026-14847MEDIUM4.3The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of i...
CVE-2026-14845MEDIUM6.1The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor re...
CVE-2026-14843MEDIUM5.3The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target...