CVE Vulnerability Database
Search and browse 383,855 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13110 | MEDIUM | 5.3 | — | Jul 28, 2026 | The Storegrowth Sales Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to and includin... |
| CVE-2026-65880 | CRITICAL | 10 | — | Jul 28, 2026 | Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form proce... |
| CVE-2026-63303 | MEDIUM | 5.1 | 0.4% | Jul 28, 2026 | A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai... |
| CVE-2026-63302 | MEDIUM | 5.1 | 0.3% | Jul 28, 2026 | Quick.CMS is vulnerable to Local File Inclusion (LFI) in the admin.php endpoint via the p parameter. An authenticated at... |
| CVE-2026-63301 | HIGH | 7 | 0.4% | Jul 28, 2026 | In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding... |
| CVE-2026-18029 | MEDIUM | 6.3 | 0.2% | Jul 28, 2026 | Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a s... |
| CVE-2026-18028 | LOW | 2.3 | 0.2% | Jul 28, 2026 | The "quick setup" view presented to users after they first create an event allows to set up the most critical parts of ... |
| CVE-2026-17072 | LOW | 3.3 | — | Jul 28, 2026 | A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC... |
| CVE-2026-65624 | MEDIUM | 6.9 | 0.4% | Jul 28, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows an unauthenticated remote ... |
| CVE-2026-59248 | HIGH | 8.7 | 0.3% | Jul 28, 2026 | Allocation of resources without limits vulnerability in ninenines cowlib allows an unauthenticated remote HTTP/2 or HTTP... |
| CVE-2026-58246 | MEDIUM | 4.3 | — | Jul 28, 2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn... |
| CVE-2026-16462 | CRITICAL | 9.8 | 0.4% | Jul 28, 2026 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker ... |
| CVE-2026-14785 | HIGH | 7.5 | — | Jul 28, 2026 | The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver... |
| CVE-2026-14328 | HIGH | 8.8 | — | Jul 28, 2026 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privil... |
| CVE-2026-11841 | CRITICAL | 9.4 | 0.5% | Jul 28, 2026 | An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac... |
| CVE-2026-11598 | MEDIUM | 5 | — | Jul 28, 2026 | The Shortcodify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'name' Shortcode Attribute in all ... |
| CVE-2026-10207 | HIGH | 7.5 | — | Jul 28, 2026 | The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.... |
| CVE-2026-9680 | MEDIUM | 5.8 | 0.2% | Jul 28, 2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP... |
| CVE-2026-8167 | MEDIUM | 6.1 | 0.1% | Jul 28, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in THEWP Digital Solu... |
| CVE-2026-61376 | HIGH | 8.6 | 1.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.... |
| CVE-2026-59764 | HIGH | 8.6 | 1.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu... |
| CVE-2026-44387 | MEDIUM | 5.2 | 0.1% | Jul 28, 2026 | ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. I... |
| CVE-2026-15267 | MEDIUM | 6.5 | 0.3% | Jul 28, 2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQL ... |
| CVE-2026-14516 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec... |
| CVE-2026-14171 | MEDIUM | 6.1 | 0.2% | Jul 28, 2026 | An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ... |
