CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-35147
8.2 HIGH

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific …

Jul 16, 2026
CVE-2026-35146
6.3 MEDIUM

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could …

Jul 16, 2026
CVE-2023-49900
9.8 CRITICAL

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

Jul 16, 2026
CVE-2023-49899
9.8 CRITICAL

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

Jul 16, 2026
CVE-2026-22752
9.6 CRITICAL

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through …

Jul 16, 2026
CVE-2026-7543
7.2 HIGH

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient …

Jul 16, 2026
CVE-2026-6424

Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system

Jul 16, 2026
CVE-2026-6423

A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authentication in an IPC channel.

Jul 16, 2026
CVE-2026-58078

The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

Jul 16, 2026
CVE-2026-15727
4.9 MEDIUM

The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 …

Jul 16, 2026
CVE-2026-15651
4.9 MEDIUM

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, …

Jul 16, 2026
CVE-2026-15610
4.3 MEDIUM

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 16, 2026
CVE-2026-15407
4.3 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin …

Jul 16, 2026
CVE-2026-15350
4.3 MEDIUM

The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the …

Jul 16, 2026
CVE-2026-15324
4.4 MEDIUM

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter …

Jul 16, 2026
CVE-2026-15106
5.3 MEDIUM

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 16, 2026
CVE-2026-15103
8.8 HIGH

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update …

Jul 16, 2026
CVE-2026-15099
6.4 MEDIUM

The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This …

Jul 16, 2026
CVE-2026-15022
6.5 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all …

Jul 16, 2026
CVE-2026-15021
6.4 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due …

Jul 16, 2026
CVE-2026-15008
8.1 HIGH

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file …

Jul 16, 2026
CVE-2026-15005
8.8 HIGH

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing …

Jul 16, 2026
CVE-2026-13767
6.5 MEDIUM

The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This …

Jul 16, 2026
CVE-2026-13755
6.4 MEDIUM

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up …

Jul 16, 2026
CVE-2026-13754
6.5 MEDIUM

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up …

Jul 16, 2026
CVE-2026-13741
8.8 HIGH

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This …

Jul 16, 2026
CVE-2026-15925

Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname …

Jul 16, 2026
CVE-2026-12979
5.5 MEDIUM

The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges …

Jul 16, 2026
CVE-2026-12978
7.1 HIGH

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX …

Jul 16, 2026
CVE-2026-12907
2.7 LOW

The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least …

Jul 16, 2026
CVE-2026-12906
2.7 LOW

The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, …

Jul 16, 2026
CVE-2026-12869
6.1 MEDIUM

The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts …

Jul 16, 2026
CVE-2026-12684
6.5 MEDIUM

The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions …

Jul 16, 2026
CVE-2026-12585
8.1 HIGH

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting …

Jul 16, 2026
CVE-2026-12525
8.8 HIGH

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with …

Jul 16, 2026
CVE-2026-12510
5.9 MEDIUM

The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with …

Jul 16, 2026
CVE-2026-12492
9.8 CRITICAL

The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user …

Jul 16, 2026
CVE-2026-12395
6.5 MEDIUM

The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated …

Jul 16, 2026
CVE-2026-11866
5.4 MEDIUM

The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing …

Jul 16, 2026
CVE-2026-11371
6.1 MEDIUM

The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is …

Jul 16, 2026
CVE-2026-53366
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch …

Jul 16, 2026
CVE-2026-15458
4.9 MEDIUM

The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due …

Jul 16, 2026
CVE-2026-15445
4.9 MEDIUM

The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due …

Jul 16, 2026
CVE-2026-15306
6.1 MEDIUM

The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter …

Jul 16, 2026
CVE-2026-15013
9.8 CRITICAL

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up …

Jul 16, 2026
CVE-2026-13042
7.2 HIGH

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to …

Jul 16, 2026
CVE-2026-21729
7.5 HIGH

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Jul 16, 2026
CVE-2026-15652
6.4 MEDIUM

The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in …

Jul 16, 2026
CVE-2026-15336
4.3 MEDIUM

The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the …

Jul 16, 2026
CVE-2026-14987
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.