CVE Vulnerability Database

Search and browse 389,869 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-1617CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Turkmesh Communica...
CVE-2026-16461MEDIUM6.5A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), v...
CVE-2026-64606CRITICAL9.8Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lamb...
CVE-2026-64609CRITICAL9.1Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVa...
CVE-2026-64608CRITICAL9.8Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compa...
CVE-2026-62415CRITICAL9.1Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membe...
CVE-2026-1771HIGH7.2The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFi...
CVE-2026-1372MEDIUM4.3The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in...
CVE-2026-15370HIGH7.3A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concaten...
CVE-2026-15145MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-8593MEDIUM5.3Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, ...
CVE-2026-3183HIGH7.1Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.
CVE-2026-8082HIGH7.5The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQ...
CVE-2026-14185MEDIUM4.3The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-...
CVE-2026-14184MEDIUM5.4The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of...
CVE-2026-14183MEDIUM4.3The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han...
CVE-2026-13694MEDIUM6.5The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated tr...
CVE-2026-13693MEDIUM5.9The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the ...
CVE-2026-11767HIGH8.8The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values bef...
CVE-2026-3182MEDIUM4.3Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive ...
CVE-2026-16266MEDIUM6.3Versions of the package mongo-object before 3.0.3 are vulnerable to Prototype Pollution via the expandKey() function in ...
CVE-2026-15927MEDIUM6.8A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints...
CVE-2026-15812MEDIUM4.8A vulnerability was found in the internal Access Control List (ACL) subsystem of kronosnet (Version affected: <= 1.34). ...
CVE-2026-15811MEDIUM5.8A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not...
CVE-2026-15782MEDIUM4.9The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPres...