CVE Vulnerability Database

Search and browse 384,318 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15755MEDIUM6.4The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Short...
CVE-2026-15665MEDIUM6.4The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-15653MEDIUM6.4The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2026-15648MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attri...
CVE-2026-15464MEDIUM6.4The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Att...
CVE-2026-15334MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-15333MEDIUM6.4The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress...
CVE-2026-12654MEDIUM5.3The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up...
CVE-2026-14603HIGH7.5The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint...
CVE-2026-14172HIGH7.8Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without ...
CVE-2026-12981HIGH7.5The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user pas...
CVE-2026-12877CRITICAL9.1The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user s...
CVE-2026-12690LOW3.8The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, ...
CVE-2026-12689MEDIUM5.4The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr...
CVE-2026-12688MEDIUM6.5The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group mem...
CVE-2026-12497HIGH7.5The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2026-16870HIGH8.8Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execut...
CVE-2026-66141HIGH7.8Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
CVE-2026-66140HIGH7.8Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege...
CVE-2026-66139MEDIUM4.8OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
CVE-2026-66138HIGH7.2In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code ...
CVE-2026-54422MEDIUM5.5In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, m...
CVE-2026-6454MEDIUM6.4The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and inclu...
CVE-2026-15420MEDIUM4.3The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory ...
CVE-2026-15100MEDIUM6.4The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnore...