CVE Vulnerability Database

Search and browse 386,269 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-15646MEDIUM6.4The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri...
CVE-2026-15448MEDIUM6.5The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order...
CVE-2026-15404MEDIUM6.4The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc...
CVE-2026-15394MEDIUM6.4The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross...
CVE-2026-15348MEDIUM6.3The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all...
CVE-2026-15017HIGH8.8The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin...
CVE-2026-15015CRITICAL9.8The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-15011CRITICAL9.8The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame...
CVE-2026-14481MEDIUM6.4The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl...
CVE-2026-14282CRITICAL9.8The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for ...
CVE-2026-13119MEDIUM6.5The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan...
CVE-2026-13009MEDIUM6.5The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param...
CVE-2026-52688HIGH7.5RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation
CVE-2026-52686LOW3.7The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat...
CVE-2026-52684LOW3.7If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data...
CVE-2026-16723CRITICAL9A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ...
CVE-2026-16287HIGH7.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG...
CVE-2024-58330HIGH7.5A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret...
CVE-2024-58023HIGH8.4Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform...
CVE-2026-9729MEDIUM6.4The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti...
CVE-2026-9713HIGH7.5The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'...
CVE-2026-9635MEDIUM6.4The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame...
CVE-2026-59678HIGH7.1An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi...
CVE-2026-59677MEDIUM6.8A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ...
CVE-2026-12421HIGH7.2The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version...