CVE Vulnerability Database
Search and browse 389,943 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11371 | MEDIUM | 6.1 | — | Jul 16, 2026 | The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and... |
| CVE-2026-53366 | HIGH | 7.8 | 0.2% | Jul 16, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation p... |
| CVE-2026-15458 | MEDIUM | 4.9 | 0.3% | Jul 16, 2026 | The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio... |
| CVE-2026-15445 | MEDIUM | 4.9 | — | Jul 16, 2026 | The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio... |
| CVE-2026-15306 | MEDIUM | 6.1 | 0.2% | Jul 16, 2026 | The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflec... |
| CVE-2026-15013 | CRITICAL | 9.8 | 0.4% | Jul 16, 2026 | The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algor... |
| CVE-2026-13042 | HIGH | 7.2 | 0.2% | Jul 16, 2026 | The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions... |
| CVE-2026-21729 | HIGH | 7.5 | 0.3% | Jul 16, 2026 | Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depe... |
| CVE-2026-15652 | MEDIUM | 6.4 | 0.2% | Jul 16, 2026 | The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-15336 | MEDIUM | 4.3 | 0.3% | Jul 16, 2026 | The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin... |
| CVE-2026-14987 | MEDIUM | 6.4 | 0.2% | Jul 16, 2026 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-13005 | MEDIUM | 4.4 | 0.2% | Jul 16, 2026 | The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2026-12941 | MEDIUM | 6.5 | 0.3% | Jul 16, 2026 | The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generi... |
| CVE-2026-12753 | HIGH | 7.5 | 0.3% | Jul 16, 2026 | The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Inject... |
| CVE-2026-12434 | MEDIUM | 4.3 | 0.2% | Jul 16, 2026 | The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and ... |
| CVE-2026-12409 | MEDIUM | 4.3 | 0.1% | Jul 16, 2026 | The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress i... |
| CVE-2026-48863 | HIGH | 7.5 | 0.8% | Jul 16, 2026 | A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to... |
| CVE-2026-3842 | HIGH | 7.8 | 0.2% | Jul 16, 2026 | A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond... |
| CVE-2026-23538 | HIGH | 7.5 | 0.7% | Jul 16, 2026 | A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establi... |
| CVE-2026-1609 | HIGH | 8.1 | 0.5% | Jul 16, 2026 | A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user ac... |
| CVE-2026-15909 | MEDIUM | 6.3 | 0.2% | Jul 16, 2026 | A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is a... |
| CVE-2026-15907 | HIGH | 7.3 | 0.3% | Jul 16, 2026 | A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=... |
| CVE-2026-63175 | HIGH | 7.1 | 0.3% | Jul 15, 2026 | PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than in... |
| CVE-2026-62314 | MEDIUM | 5.8 | 0.3% | Jul 15, 2026 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap... |
| CVE-2026-55652 | CRITICAL | 9.8 | 0.4% | Jul 15, 2026 | Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequest... |
