CVE Vulnerability Database
Search and browse 381,202 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14834 | MEDIUM | 6.5 | 0.1% | Jul 31, 2026 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX ... |
| CVE-2026-14833 | MEDIUM | 6.8 | — | Jul 31, 2026 | The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rend... |
| CVE-2026-14830 | HIGH | 7.5 | — | Jul 31, 2026 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually... |
| CVE-2026-14554 | MEDIUM | 6.5 | 0.2% | Jul 31, 2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them... |
| CVE-2026-14483 | CRITICAL | 9.8 | 0.6% | Jul 31, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all ver... |
| CVE-2026-14333 | HIGH | 7.5 | — | Jul 31, 2026 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a p... |
| CVE-2026-14319 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurri... |
| CVE-2026-14317 | MEDIUM | 5.3 | — | Jul 31, 2026 | The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t... |
| CVE-2026-13609 | HIGH | 8.8 | 0.2% | Jul 31, 2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value af... |
| CVE-2026-13393 | LOW | 3.5 | 0.2% | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item... |
| CVE-2026-13392 | HIGH | 7.2 | 0.2% | Jul 31, 2026 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a... |
| CVE-2026-12721 | HIGH | 8.6 | 0.2% | Jul 31, 2026 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us... |
| CVE-2026-12720 | HIGH | 7.5 | 0.2% | Jul 31, 2026 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data ... |
| CVE-2026-12697 | MEDIUM | 5.4 | 0.1% | Jul 31, 2026 | The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us... |
| CVE-2026-12695 | HIGH | 8.1 | 0.2% | Jul 31, 2026 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted... |
| CVE-2026-12376 | MEDIUM | 4.3 | 0.1% | Jul 31, 2026 | The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing... |
| CVE-2026-12251 | HIGH | 8.1 | 0.1% | Jul 31, 2026 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it m... |
| CVE-2026-63223 | CRITICAL | 9.8 | 0.5% | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not i... |
| CVE-2026-63222 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument us... |
| CVE-2026-63221 | CRITICAL | 9.4 | — | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound v... |
| CVE-2026-56673 | HIGH | 7.5 | 0.4% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_path... |
| CVE-2026-56672 | HIGH | 8.2 | — | Jul 31, 2026 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-control... |
| CVE-2026-56671 | HIGH | 7.5 | 0.7% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_previ... |
| CVE-2026-56670 | HIGH | 8.2 | 0.2% | Jul 31, 2026 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpo... |
| CVE-2026-63220 | MEDIUM | 4.8 | — | Jul 31, 2026 | CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For... |
