CVE Vulnerability Database
Search and browse 384,318 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15755 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short... |
| CVE-2026-15665 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-15653 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-15648 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri... |
| CVE-2026-15464 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att... |
| CVE-2026-15334 | MEDIUM | 6.4 | 0.3% | Jul 24, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
| CVE-2026-15333 | MEDIUM | 6.4 | 0.3% | Jul 24, 2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress... |
| CVE-2026-12654 | MEDIUM | 5.3 | 0.4% | Jul 24, 2026 | The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up... |
| CVE-2026-14603 | HIGH | 7.5 | 0.1% | Jul 24, 2026 | The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint... |
| CVE-2026-14172 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ... |
| CVE-2026-12981 | HIGH | 7.5 | 0.2% | Jul 24, 2026 | The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas... |
| CVE-2026-12877 | CRITICAL | 9.1 | 0.1% | Jul 24, 2026 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s... |
| CVE-2026-12690 | LOW | 3.8 | 0.1% | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, ... |
| CVE-2026-12689 | MEDIUM | 5.4 | 0.1% | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr... |
| CVE-2026-12688 | MEDIUM | 6.5 | 0.1% | Jul 24, 2026 | The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem... |
| CVE-2026-12497 | HIGH | 7.5 | 0.1% | Jul 24, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2026-16870 | HIGH | 8.8 | 0.4% | Jul 24, 2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execut... |
| CVE-2026-66141 | HIGH | 7.8 | 0.1% | Jul 24, 2026 | Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled. |
| CVE-2026-66140 | HIGH | 7.8 | 0.3% | Jul 24, 2026 | Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege... |
| CVE-2026-66139 | MEDIUM | 4.8 | 0.3% | Jul 24, 2026 | OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known. |
| CVE-2026-66138 | HIGH | 7.2 | 0.4% | Jul 24, 2026 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code ... |
| CVE-2026-54422 | MEDIUM | 5.5 | — | Jul 24, 2026 | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m... |
| CVE-2026-6454 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu... |
| CVE-2026-15420 | MEDIUM | 4.3 | 0.6% | Jul 24, 2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory ... |
| CVE-2026-15100 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore... |
