CVE Vulnerability Database
Search and browse 386,032 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12982 | MEDIUM | 6.1 | — | Jul 27, 2026 | The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it... |
| CVE-2026-12493 | HIGH | 7.5 | — | Jul 27, 2026 | The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved ext... |
| CVE-2026-12394 | CRITICAL | 9.8 | — | Jul 27, 2026 | The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing ... |
| CVE-2026-12255 | HIGH | 8.1 | — | Jul 27, 2026 | The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration reques... |
| CVE-2026-10082 | MEDIUM | 6.1 | — | Jul 27, 2026 | The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it... |
| CVE-2025-15662 | HIGH | 8.6 | — | Jul 27, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl... |
| CVE-2026-15928 | HIGH | 8.2 | — | Jul 27, 2026 | XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in... |
| CVE-2026-17501 | MEDIUM | 6.9 | 0.4% | Jul 27, 2026 | A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file commo... |
| CVE-2026-17500 | MEDIUM | 6.9 | — | Jul 27, 2026 | A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file... |
| CVE-2026-57990 | HIGH | 7.4 | 0.9% | Jul 26, 2026 | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker t... |
| CVE-2026-57989 | HIGH | 7.4 | 0.4% | Jul 26, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over ... |
| CVE-2026-57978 | MEDIUM | 5.4 | 0.2% | Jul 26, 2026 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne... |
| CVE-2026-17497 | HIGH | 8.3 | 0.5% | Jul 26, 2026 | NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar... |
| CVE-2026-17496 | HIGH | 8.1 | 0.3% | Jul 26, 2026 | NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into t... |
| CVE-2026-17459 | MEDIUM | 4.3 | 0.3% | Jul 26, 2026 | A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter... |
| CVE-2026-17458 | MEDIUM | 6.3 | 0.2% | Jul 26, 2026 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file s... |
| CVE-2026-17457 | MEDIUM | 4.3 | 0.3% | Jul 26, 2026 | A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserN... |
| CVE-2026-64530 | CRITICAL | 9.8 | 0.5% | Jul 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_q... |
| CVE-2024-14040 | HIGH | 7.8 | 0.1% | Jul 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS netwo... |
| CVE-2026-63720 | HIGH | 7.5 | 0.4% | Jul 26, 2026 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who contr... |
| CVE-2026-17434 | MEDIUM | 6.3 | 0.2% | Jul 26, 2026 | A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/mod... |
| CVE-2026-17433 | MEDIUM | 5.3 | 0.1% | Jul 26, 2026 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of t... |
| CVE-2026-15962 | HIGH | 8.8 | 0.4% | Jul 26, 2026 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i... |
| CVE-2026-17432 | MEDIUM | 5 | 0.2% | Jul 26, 2026 | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functio... |
| CVE-2026-10681 | HIGH | 7 | 0.1% | Jul 25, 2026 | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thre... |
