CVE Vulnerability Database
Search and browse 386,269 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15646 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attri... |
| CVE-2026-15448 | MEDIUM | 6.5 | — | Jul 23, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order... |
| CVE-2026-15404 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and inc... |
| CVE-2026-15394 | MEDIUM | 6.4 | — | Jul 23, 2026 | The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-15348 | MEDIUM | 6.3 | — | Jul 23, 2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all... |
| CVE-2026-15017 | HIGH | 8.8 | — | Jul 23, 2026 | The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin... |
| CVE-2026-15015 | CRITICAL | 9.8 | — | Jul 23, 2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions u... |
| CVE-2026-15011 | CRITICAL | 9.8 | 1.0% | Jul 23, 2026 | The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parame... |
| CVE-2026-14481 | MEDIUM | 6.4 | 0.4% | Jul 23, 2026 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerabl... |
| CVE-2026-14282 | CRITICAL | 9.8 | 1.3% | Jul 23, 2026 | The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for ... |
| CVE-2026-13119 | MEDIUM | 6.5 | — | Jul 23, 2026 | The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan... |
| CVE-2026-13009 | MEDIUM | 6.5 | — | Jul 23, 2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Param... |
| CVE-2026-52688 | HIGH | 7.5 | 0.4% | Jul 23, 2026 | RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation |
| CVE-2026-52686 | LOW | 3.7 | 0.3% | Jul 23, 2026 | The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat... |
| CVE-2026-52684 | LOW | 3.7 | 0.2% | Jul 23, 2026 | If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data... |
| CVE-2026-16723 | CRITICAL | 9 | 0.7% | Jul 23, 2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable ... |
| CVE-2026-16287 | HIGH | 7.8 | 0.8% | Jul 23, 2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG... |
| CVE-2024-58330 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to ret... |
| CVE-2024-58023 | HIGH | 8.4 | 0.1% | Jul 23, 2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive inform... |
| CVE-2026-9729 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_noti... |
| CVE-2026-9713 | HIGH | 7.5 | 0.5% | Jul 23, 2026 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'... |
| CVE-2026-9635 | MEDIUM | 6.4 | 0.3% | Jul 23, 2026 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parame... |
| CVE-2026-59678 | HIGH | 7.1 | 0.2% | Jul 23, 2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary fi... |
| CVE-2026-59677 | MEDIUM | 6.8 | 0.1% | Jul 23, 2026 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined ... |
| CVE-2026-12421 | HIGH | 7.2 | 0.3% | Jul 23, 2026 | The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version... |
