CVE Vulnerability Database

Search and browse 385,564 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13726HIGH7.1The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons...
CVE-2026-13714CRITICAL9.8The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded f...
CVE-2026-13597CRITICAL9.1The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check alwa...
CVE-2026-13400MEDIUM6.1Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl...
CVE-2026-13390MEDIUM5.3The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega...
CVE-2026-13332CRITICAL9.1The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX acti...
CVE-2026-13152HIGH8.1The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registrat...
CVE-2026-12982MEDIUM6.1The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it...
CVE-2026-12493HIGH7.5The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext...
CVE-2026-12394CRITICAL9.8The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing ...
CVE-2026-12255HIGH8.1The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques...
CVE-2026-10082MEDIUM6.1The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it...
CVE-2025-15662HIGH8.6The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl...
CVE-2026-15928HIGH8.2XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in...
CVE-2026-17501MEDIUM6.9A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file commo...
CVE-2026-17500MEDIUM6.9A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file...
CVE-2026-57990HIGH7.4Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t...
CVE-2026-57989HIGH7.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ...
CVE-2026-57978MEDIUM5.4Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne...
CVE-2026-17497HIGH8.3NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar...
CVE-2026-17496HIGH8.1NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t...
CVE-2026-17459MEDIUM4.3A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter...
CVE-2026-17458MEDIUM6.3A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file s...
CVE-2026-17457MEDIUM4.3A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserN...
CVE-2026-64530CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_q...