CVE Vulnerability Database

Search and browse 383,855 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13110MEDIUM5.3The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin...
CVE-2026-65880CRITICAL10Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form proce...
CVE-2026-63303MEDIUM5.1A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai...
CVE-2026-63302MEDIUM5.1Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated at...
CVE-2026-63301HIGH7In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding...
CVE-2026-18029MEDIUM6.3Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s...
CVE-2026-18028LOW2.3The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of ...
CVE-2026-17072LOW3.3A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC...
CVE-2026-65624MEDIUM6.9Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote ...
CVE-2026-59248HIGH8.7Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP...
CVE-2026-58246MEDIUM4.3SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn...
CVE-2026-16462CRITICAL9.8In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker ...
CVE-2026-14785HIGH7.5The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver...
CVE-2026-14328HIGH8.8The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil...
CVE-2026-11841CRITICAL9.4An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac...
CVE-2026-11598MEDIUM5The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all ...
CVE-2026-10207HIGH7.5The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2....
CVE-2026-9680MEDIUM5.8Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP...
CVE-2026-8167MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu...
CVE-2026-61376HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings....
CVE-2026-59764HIGH8.6ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu...
CVE-2026-44387MEDIUM5.2ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I...
CVE-2026-15267MEDIUM6.5The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL ...
CVE-2026-14516HIGH7.5The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec...
CVE-2026-14171MEDIUM6.1An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ...