CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-1832
4.3 MEDIUM

The ThriveDesk – Live Chat, AI Chatbot, Helpdesk & Knowledge Base plugin for WordPress is vulnerable to unauthorized cache deletion due to a missing capability …

Jul 11, 2026
CVE-2026-15335
7.5 HIGH

The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in all versions up to, and including, 1.7.20 …

Jul 11, 2026
CVE-2026-15097
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'height_slider' Slider Module Field in all versions up to, and including, 7.7.6 …

Jul 11, 2026
CVE-2026-15096
6.4 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Map Module 'b_width_map' Field in all versions up to, and including, 7.7.6 …

Jul 11, 2026
CVE-2026-14262
8.8 HIGH

The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication Bypass to Privilege Escalation in …

Jul 11, 2026
CVE-2026-13250
5.3 MEDIUM

The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin …

Jul 11, 2026
CVE-2026-13116
4.3 MEDIUM

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Jul 11, 2026
CVE-2026-12141
4.9 MEDIUM

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in …

Jul 11, 2026
CVE-2025-13968
6.4 MEDIUM

The Starboard Suite Reservation Calendars plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in the [starboard-suite-lightbox] shortcode in all versions up …

Jul 11, 2026
CVE-2026-8678
4.3 MEDIUM

The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not …

Jul 11, 2026
CVE-2026-7544
4.3 MEDIUM

The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This …

Jul 11, 2026
CVE-2026-5743
6.4 MEDIUM

The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, …

Jul 11, 2026
CVE-2026-3367
4.4 MEDIUM

The Lockme OAuth2 calendars integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'App ID' setting in all versions up to, and …

Jul 11, 2026
CVE-2026-15338
7.5 HIGH

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the …

Jul 11, 2026
CVE-2026-15073
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions …

Jul 11, 2026
CVE-2026-15072
6.5 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions …

Jul 11, 2026
CVE-2026-13353
8.8 HIGH

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in …

Jul 11, 2026
CVE-2026-13262
6.5 MEDIUM

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter …

Jul 11, 2026
CVE-2026-13114
7.2 HIGH

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info …

Jul 11, 2026
CVE-2026-12426
5.3 MEDIUM

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Jul 11, 2026
CVE-2026-10628
4.3 MEDIUM

The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.10.0. This is due …

Jul 11, 2026
CVE-2026-13756
8.8 HIGH

The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing …

Jul 11, 2026
CVE-2026-11426
6.5 MEDIUM

The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.76. This is due to the …

Jul 11, 2026
CVE-2026-55175
7.5 HIGH

Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations …

Jul 10, 2026
CVE-2026-44383
7.5 HIGH

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP …

Jul 10, 2026
CVE-2026-42952
7.5 HIGH

Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.

Jul 10, 2026
CVE-2026-20744
9.8 CRITICAL

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

Jul 10, 2026
CVE-2026-15089
9.1 CRITICAL

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

Jul 10, 2026
CVE-2026-15087
5.9 MEDIUM

vulnerability in Drupal Clean RESTful allows . This issue affects Clean RESTful versions: *.*.

Jul 10, 2026
CVE-2026-15086
5.9 MEDIUM

vulnerability in Drupal Raw Formatter [Meta Tag Formatter] allows . This issue affects Raw Formatter [Meta Tag Formatter] versions: *.*.

Jul 10, 2026
CVE-2026-14480
9.9 CRITICAL

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly …

Jul 10, 2026
CVE-2026-14286

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 10, 2026
CVE-2026-11915
5.9 MEDIUM

vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.

Jul 10, 2026
CVE-2026-11914
5.9 MEDIUM

vulnerability in Drupal Composer allows . This issue affects Composer versions: *.*.

Jul 10, 2026
CVE-2026-11913
9.8 CRITICAL

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

Jul 10, 2026
CVE-2026-59155

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to 2.2.5, the GET /api/v1/ddns and GET /api/v1/notification endpoints return full …

Jul 10, 2026
CVE-2026-58591
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 …

Jul 10, 2026
CVE-2026-58590
5.4 MEDIUM

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

Jul 10, 2026
CVE-2026-58589
5.4 MEDIUM

Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.

Jul 10, 2026
CVE-2026-58588
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: …

Jul 10, 2026
CVE-2026-58587
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal Canvas allows Cross-Site Scripting (XSS). This issue affects Drupal Canvas versions: …

Jul 10, 2026
CVE-2026-58503

Frappe is a full-stack web application framework. Prior to 16.16.0 and 15.106.0, user enumeration could be performed via the reset_password endpoint. This issue is fixed …

Jul 10, 2026
CVE-2026-57584

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled …

Jul 10, 2026
CVE-2026-55884

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on a gorilla/mux …

Jul 10, 2026
CVE-2026-55883

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.24.0 through 0.37.3, the Tilt HUD WebSocket at /ws/view is gated by a …

Jul 10, 2026
CVE-2026-55882

Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.19.5 through 0.37.3, the Tilt HUD server mounts Go net/http/pprof handlers under /debug …

Jul 10, 2026
CVE-2026-55852

Frappe is a full-stack web application framework. Prior to 16.23.0 and 15.112.0, TarSlip RCE was possible in Package Import because tarfile members were not sufficiently …

Jul 10, 2026
CVE-2026-55810
8.1 HIGH

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

Jul 10, 2026
CVE-2026-55809
8.1 HIGH

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 …

Jul 10, 2026
CVE-2026-55808
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: …

Jul 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.