CVE Vulnerability Database
Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13577 | HIGH | 8.2 | 0.3% | Jul 20, 2026 | Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan... |
| CVE-2026-9833 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape... |
| CVE-2026-8825 | MEDIUM | 4.9 | 0.1% | Jul 20, 2026 | The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p... |
| CVE-2026-6656 | HIGH | 7.5 | 0.1% | Jul 20, 2026 | Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu... |
| CVE-2026-16235 | CRITICAL | 9.8 | 0.1% | Jul 20, 2026 | Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-... |
| CVE-2026-13432 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing a... |
| CVE-2026-13156 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it veri... |
| CVE-2026-13147 | CRITICAL | 9.1 | 0.1% | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowi... |
| CVE-2026-13142 | HIGH | 8.1 | 0.1% | Jul 20, 2026 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a wo... |
| CVE-2026-12973 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i... |
| CVE-2026-12972 | MEDIUM | 5.3 | 0.2% | Jul 20, 2026 | The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i... |
| CVE-2026-12970 | HIGH | 7.1 | 0.2% | Jul 20, 2026 | The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri... |
| CVE-2026-12898 | MEDIUM | 6.5 | 0.2% | Jul 20, 2026 | The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be... |
| CVE-2026-12724 | MEDIUM | 4.3 | 0.1% | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re... |
| CVE-2026-12723 | MEDIUM | 5.3 | 0.1% | Jul 20, 2026 | The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u... |
| CVE-2026-12592 | HIGH | 7.5 | 0.2% | Jul 20, 2026 | The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu... |
| CVE-2026-11868 | MEDIUM | 5.3 | 0.1% | Jul 20, 2026 | The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio... |
| CVE-2026-11349 | HIGH | 8.6 | 0.2% | Jul 20, 2026 | The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0... |
| CVE-2026-10755 | LOW | 2.7 | 0.2% | Jul 20, 2026 | The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST ... |
| CVE-2026-10724 | MEDIUM | 4.8 | 0.1% | Jul 20, 2026 | The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review... |
| CVE-2026-10081 | HIGH | 8.8 | 0.3% | Jul 20, 2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe... |
| CVE-2026-45138 | MEDIUM | 5.4 | 0.1% | Jul 20, 2026 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` v... |
| CVE-2026-44359 | CRITICAL | 10 | 1.0% | Jul 20, 2026 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository... |
| CVE-2026-42566 | HIGH | 7.5 | 0.3% | Jul 20, 2026 | Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User... |
| CVE-2026-12484 | HIGH | 7.8 | 0.2% | Jul 19, 2026 | A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d... |
