CVE Vulnerability Database

Search and browse 383,844 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18072CRITICAL9.8The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to ...
CVE-2026-5626MEDIUM4.3The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec...
CVE-2026-15344MEDIUM4.9The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver...
CVE-2026-12476HIGH7.2The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3...
CVE-2026-17166MEDIUM4.3The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress...
CVE-2026-17162MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-17161MEDIUM6.4The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2026-15735MEDIUM6.4The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field'...
CVE-2026-12939MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the p...
CVE-2026-12938MEDIUM6.4The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the...
CVE-2026-12144HIGH8.8The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl...
CVE-2026-56822HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-56821HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-66064MEDIUM5.3goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler...
CVE-2026-66063MEDIUM6.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown....
CVE-2026-64863CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server....
CVE-2026-62325CRITICAL9.1goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver...
CVE-2026-59921MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54719HIGH7.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown....
CVE-2026-54659MEDIUM6.9Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18...
CVE-2026-54658CRITICAL9.8Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/u...
CVE-2026-54650HIGH8.6openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ...
CVE-2026-54638HIGH7.5gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted...
CVE-2026-47219HIGH7.5find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w...
CVE-2026-55415HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...