CVE Vulnerability Database

Search and browse 383,857 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-14516HIGH7.5The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec...
CVE-2026-14171MEDIUM6.1An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ...
CVE-2026-14170Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-14169HIGH8.1Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in...
CVE-2026-14168HIGH8.8A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th...
CVE-2026-14167HIGH8.8A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu...
CVE-2026-13161HIGH7.5The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi...
CVE-2026-12800HIGH7.5The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'...
CVE-2026-55977LOW3.3Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio...
CVE-2026-15730MEDIUM6.4The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ...
CVE-2026-15673MEDIUM4.4The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15671MEDIUM4.9The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15670MEDIUM4.9The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-15014CRITICAL9.8The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera...
CVE-2026-12741HIGH7.5The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via t...
CVE-2026-11756CRITICAL10A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3...
CVE-2024-14041MEDIUM5.9In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno...
CVE-2026-6251MEDIUM6.5The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i...
CVE-2026-16811MEDIUM4.9The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas...
CVE-2026-16797MEDIUM4.3The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure...
CVE-2026-16587MEDIUM4.3The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in...
CVE-2026-16585HIGH7.2The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbi...
CVE-2026-15136MEDIUM4.3The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery...
CVE-2026-15012MEDIUM5.3The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C...
CVE-2026-14926MEDIUM4.2The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the ...