CVE Vulnerability Database

Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9656MEDIUM4.3The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information ...
CVE-2026-15380MEDIUM5.1A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — n...
CVE-2026-15379MEDIUM5.1The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents ...
CVE-2026-9810CRITICAL9.8The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any val...
CVE-2026-13402MEDIUM5.3The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the tem...
CVE-2026-12393MEDIUM5.4The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requ...
CVE-2026-11966MEDIUM5.3The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticate...
CVE-2026-11961HIGH8.1The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted d...
CVE-2026-11575HIGH7.5The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming paymen...
CVE-2026-10525MEDIUM6.1The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and...
CVE-2019-25764HIGH7.3**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a loca...
CVE-2026-15982CRITICAL9.8The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable ...
CVE-2026-15094MEDIUM6.1The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parame...
CVE-2026-60060MEDIUM6.3Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provide...
CVE-2026-58317MEDIUM6.3Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Pr...
CVE-2026-41993MEDIUM6.7Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a loc...
CVE-2026-21770MEDIUM6.5HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker ...
CVE-2026-15759MEDIUM6.4The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable t...
CVE-2026-15457MEDIUM4.9The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa...
CVE-2026-15349MEDIUM4.3The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization b...
CVE-2026-15161MEDIUM6.4The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and ...
CVE-2026-14503MEDIUM6.5The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2026-13765HIGH7.5The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive...
CVE-2026-13352HIGH8.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-8616MEDIUM5.3The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...