CVE Vulnerability Database
Search and browse 383,857 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14516 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Injec... |
| CVE-2026-14171 | MEDIUM | 6.1 | 0.2% | Jul 28, 2026 | An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick ... |
| CVE-2026-14170 | — | — | — | Jul 28, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-14169 | HIGH | 8.1 | 0.3% | Jul 28, 2026 | Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted in... |
| CVE-2026-14168 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | A low privileged remote attacker can gain administrator privileges due to missing authorization at the insert path of th... |
| CVE-2026-14167 | HIGH | 8.8 | 0.3% | Jul 28, 2026 | A low privileged remote attacker can perform privileged configuration changes reserved for the administrator level inclu... |
| CVE-2026-13161 | HIGH | 7.5 | 0.5% | Jul 28, 2026 | The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection vi... |
| CVE-2026-12800 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'code'... |
| CVE-2026-55977 | LOW | 3.3 | 0.1% | Jul 28, 2026 | Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the applicatio... |
| CVE-2026-15730 | MEDIUM | 6.4 | 0.2% | Jul 28, 2026 | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is ... |
| CVE-2026-15673 | MEDIUM | 4.4 | 0.3% | Jul 28, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
| CVE-2026-15671 | MEDIUM | 4.9 | 0.3% | Jul 28, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
| CVE-2026-15670 | MEDIUM | 4.9 | 0.3% | Jul 28, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
| CVE-2026-15014 | CRITICAL | 9.8 | 0.5% | Jul 28, 2026 | The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera... |
| CVE-2026-12741 | HIGH | 7.5 | 0.3% | Jul 28, 2026 | The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via t... |
| CVE-2026-11756 | CRITICAL | 10 | 0.5% | Jul 28, 2026 | A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3... |
| CVE-2024-14041 | MEDIUM | 5.9 | 0.3% | Jul 28, 2026 | In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polyno... |
| CVE-2026-6251 | MEDIUM | 6.5 | 0.2% | Jul 28, 2026 | The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i... |
| CVE-2026-16811 | MEDIUM | 4.9 | 0.3% | Jul 28, 2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas... |
| CVE-2026-16797 | MEDIUM | 4.3 | 0.2% | Jul 28, 2026 | The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure... |
| CVE-2026-16587 | MEDIUM | 4.3 | 0.2% | Jul 28, 2026 | The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in... |
| CVE-2026-16585 | HIGH | 7.2 | 0.7% | Jul 28, 2026 | The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbi... |
| CVE-2026-15136 | MEDIUM | 4.3 | 0.1% | Jul 28, 2026 | The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2026-15012 | MEDIUM | 5.3 | 0.3% | Jul 28, 2026 | The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory C... |
| CVE-2026-14926 | MEDIUM | 4.2 | 0.1% | Jul 28, 2026 | The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the ... |
