CVE Vulnerability Database

Search and browse 389,905 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-13577HIGH8.2Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dan...
CVE-2026-9833HIGH7.1The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape...
CVE-2026-8825MEDIUM4.9The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning p...
CVE-2026-6656HIGH7.5Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the bu...
CVE-2026-16235CRITICAL9.8Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-...
CVE-2026-13432MEDIUM5.4The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing a...
CVE-2026-13156MEDIUM5.4The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it veri...
CVE-2026-13147CRITICAL9.1The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowi...
CVE-2026-13142HIGH8.1The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a wo...
CVE-2026-12973MEDIUM6.5The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i...
CVE-2026-12972MEDIUM5.3The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation i...
CVE-2026-12970HIGH7.1The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attri...
CVE-2026-12898MEDIUM6.5The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value be...
CVE-2026-12724MEDIUM4.3The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a re...
CVE-2026-12723MEDIUM5.3The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing u...
CVE-2026-12592HIGH7.5The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outpu...
CVE-2026-11868MEDIUM5.3The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellatio...
CVE-2026-11349HIGH8.6The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0...
CVE-2026-10755LOW2.7The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST ...
CVE-2026-10724MEDIUM4.8The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review...
CVE-2026-10081HIGH8.8The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fe...
CVE-2026-45138MEDIUM5.4CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` v...
CVE-2026-44359CRITICAL10Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository...
CVE-2026-42566HIGH7.5Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User...
CVE-2026-12484HIGH7.8A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle d...