CVE Vulnerability Database
Search and browse 381,671 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65884 | CRITICAL | 9.8 | 0.2% | Jul 29, 2026 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provide... |
| CVE-2026-50641 | HIGH | 7.1 | 0.2% | Jul 29, 2026 | Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in... |
| CVE-2026-44944 | HIGH | 8.5 | 0.1% | Jul 29, 2026 | An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control soc... |
| CVE-2026-44943 | MEDIUM | 6.9 | 0.3% | Jul 29, 2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem... |
| CVE-2026-33385 | MEDIUM | 5.1 | 0.2% | Jul 29, 2026 | A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a hig... |
| CVE-2026-14354 | HIGH | 8.7 | 0.1% | Jul 29, 2026 | CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorize... |
| CVE-2026-12927 | HIGH | 8.4 | 0.2% | Jul 29, 2026 | CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execut... |
| CVE-2026-0667 | CRITICAL | 9.3 | 0.4% | Jul 29, 2026 | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, d... |
| CVE-2026-14270 | HIGH | 8.8 | — | Jul 29, 2026 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl... |
| CVE-2026-8791 | MEDIUM | 6.4 | — | Jul 29, 2026 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` ... |
| CVE-2026-7436 | MEDIUM | 6.4 | — | Jul 29, 2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text... |
| CVE-2026-6089 | MEDIUM | 4.9 | — | Jul 29, 2026 | The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor... |
| CVE-2026-65883 | CRITICAL | 9.8 | 0.5% | Jul 29, 2026 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A fo... |
| CVE-2026-5060 | MEDIUM | 6.5 | — | Jul 29, 2026 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure D... |
| CVE-2026-56390 | MEDIUM | 6.3 | 0.1% | Jul 29, 2026 | GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi... |
| CVE-2026-56389 | HIGH | 8.6 | 0.2% | Jul 29, 2026 | GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram... |
| CVE-2026-50642 | MEDIUM | 4.8 | 0.3% | Jul 29, 2026 | diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application... |
| CVE-2026-4604 | MEDIUM | 5.3 | — | Jul 29, 2026 | The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2026-18220 | HIGH | 7.8 | — | Jul 29, 2026 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. T... |
| CVE-2026-16655 | HIGH | 7.2 | — | Jul 29, 2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne... |
| CVE-2026-16597 | HIGH | 7.2 | — | Jul 29, 2026 | The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2026-14900 | CRITICAL | 9.8 | — | Jul 29, 2026 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2026-14488 | CRITICAL | 9.1 | — | Jul 29, 2026 | The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the... |
| CVE-2026-12895 | HIGH | 7.1 | — | Jul 29, 2026 | SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries... |
| CVE-2026-65100 | MEDIUM | 6.3 | 0.3% | Jul 29, 2026 | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so... |
