CVE Vulnerability Database

Search and browse 386,032 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-64536HIGH8.1In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in is_ap_in_tkip(...
CVE-2026-64535CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch S...
CVE-2026-64534CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_unini...
CVE-2026-64533HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate lcns_follow in log_replay conver...
CVE-2026-64532HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: bound NTFS_DE view.data_off in UpdateReco...
CVE-2026-64531HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action at...
CVE-2026-14837HIGH8.5Multiple Lenze products are affected by an improper signature verification vulnerability in the SSH enablement mechanism...
CVE-2026-9830HIGH8.2The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission cal...
CVE-2026-66412HIGH7.1Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read mileston...
CVE-2026-14827MEDIUM6.8The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it in...
CVE-2026-14820MEDIUM5.3The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-log...
CVE-2026-14568MEDIUM6.5The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration Wor...
CVE-2026-14289CRITICAL9The FacturaONE para WooCommerce con VeriFactu WordPress plugin before 5.37 does not authenticate one of its request hand...
CVE-2026-14236MEDIUM4.7The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it...
CVE-2026-14235HIGH7.5The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session...
CVE-2026-14203MEDIUM4.8The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML...
CVE-2026-14190MEDIUM6.1The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input...
CVE-2026-14189LOW3.8The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them ...
CVE-2026-13726HIGH7.1The MPG WordPress plugin before 4.1.8 does not sanitise and escape a parameter before reflecting it back in the respons...
CVE-2026-13714CRITICAL9.8The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded f...
CVE-2026-13597CRITICAL9.1The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check alwa...
CVE-2026-13400MEDIUM6.1Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and incl...
CVE-2026-13390MEDIUM5.3The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggrega...
CVE-2026-13332CRITICAL9.1The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX acti...
CVE-2026-13152HIGH8.1The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registrat...