CVE Vulnerability Database
Search and browse 383,759 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12687 | HIGH | 7.5 | — | Jul 30, 2026 | The ProfileGrid WordPress plugin before 5.9.9.8 does not restrict which group an anonymous visitor may register into th... |
| CVE-2026-12500 | HIGH | 7.5 | 0.1% | Jul 30, 2026 | The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a... |
| CVE-2026-11881 | MEDIUM | 6.1 | — | Jul 30, 2026 | The Fluent Forms WordPress plugin before 6.2.6 does not sanitise and escape one of its form field configuration setting... |
| CVE-2026-11870 | MEDIUM | 5.4 | 0.2% | Jul 30, 2026 | The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a ... |
| CVE-2026-11867 | MEDIUM | 6.5 | 0.1% | Jul 30, 2026 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term ... |
| CVE-2026-11782 | MEDIUM | 5.9 | 0.1% | Jul 30, 2026 | The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a w... |
| CVE-2026-67248 | HIGH | 8.8 | 0.2% | Jul 30, 2026 | A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because ... |
| CVE-2026-67247 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlle... |
| CVE-2026-67246 | MEDIUM | 6.5 | 0.3% | Jul 30, 2026 | A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-contro... |
| CVE-2026-67245 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled... |
| CVE-2026-1360 | HIGH | 7.5 | 0.6% | Jul 30, 2026 | The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ... |
| CVE-2026-16610 | CRITICAL | 9.8 | 0.6% | Jul 30, 2026 | The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up... |
| CVE-2026-14356 | HIGH | 8.8 | — | Jul 30, 2026 | The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.... |
| CVE-2026-67244 | HIGH | 7.2 | 0.2% | Jul 30, 2026 | A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user... |
| CVE-2026-48449 | CRITICAL | 9.8 | 1.0% | Jul 30, 2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code... |
| CVE-2026-48448 | HIGH | 8.6 | 0.6% | Jul 30, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL ... |
| CVE-2026-1982 | MEDIUM | 5.3 | 0.2% | Jul 30, 2026 | The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, an... |
| CVE-2026-18188 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled... |
| CVE-2026-18187 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control... |
| CVE-2026-18186 | HIGH | 8.1 | 0.2% | Jul 30, 2026 | A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr... |
| CVE-2026-16092 | MEDIUM | 6.5 | — | Jul 30, 2026 | The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field vi... |
| CVE-2026-16727 | HIGH | 7.3 | 0.1% | Jul 30, 2026 | Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows... |
| CVE-2026-15929 | HIGH | 7.1 | 0.2% | Jul 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics Sma... |
| CVE-2026-59952 | MEDIUM | 6.9 | 0.5% | Jul 30, 2026 | Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper wh... |
| CVE-2026-18019 | MEDIUM | 4.3 | 0.1% | Jul 30, 2026 | Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cros... |
