CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-39491
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in JupiterX Core <= 4.14.1 versions.

Jun 15, 2026
CVE-2026-39489
4.4 MEDIUM

Author Arbitrary File Download in Download Monitor <= 5.1.9 versions.

Jun 15, 2026
CVE-2026-39481
7.2 HIGH

Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.

Jun 15, 2026
CVE-2026-39480
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.

Jun 15, 2026
CVE-2026-39478
8.8 HIGH

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.

Jun 15, 2026
CVE-2026-39474
8.8 HIGH

Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.

Jun 15, 2026
CVE-2026-39472
7.2 HIGH

Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

Jun 15, 2026
CVE-2026-39471
7.2 HIGH

Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

Jun 15, 2026
CVE-2026-39470
7.2 HIGH

Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.

Jun 15, 2026
CVE-2026-39468
6.8 MEDIUM

Contributor Arbitrary File Deletion in Meta Box – WordPress Custom Fields Framework <= 5.11.1 versions.

Jun 15, 2026
CVE-2026-39465
9.1 CRITICAL

Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.

Jun 15, 2026
CVE-2026-39463
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.

Jun 15, 2026
CVE-2026-39451
6.3 MEDIUM

Unauthenticated Cross Site Scripting (XSS) in WP Google Review Slider <= 18.0 versions.

Jun 15, 2026
CVE-2026-39450
7.1 HIGH

Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.

Jun 15, 2026
CVE-2026-39449
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.

Jun 15, 2026
CVE-2026-39447
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.

Jun 15, 2026
CVE-2026-39441
9.3 CRITICAL

Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.

Jun 15, 2026
CVE-2026-39435
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.

Jun 15, 2026
CVE-2026-39434
7.2 HIGH

Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.

Jun 15, 2026
CVE-2026-34902
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.

Jun 15, 2026
CVE-2026-34901
9.8 CRITICAL

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

Jun 15, 2026
CVE-2026-34900
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.

Jun 15, 2026
CVE-2026-34898
7.5 HIGH

Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.

Jun 15, 2026
CVE-2026-34892
6.5 MEDIUM

Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.

Jun 15, 2026
CVE-2026-34891
7.5 HIGH

Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.

Jun 15, 2026
CVE-2026-34886
7.5 HIGH

Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.

Jun 15, 2026
CVE-2026-27407
7.2 HIGH

Editor Privilege Escalation in AI Engine <= 3.4.9 versions.

Jun 15, 2026
CVE-2026-27333
8.1 HIGH

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.

Jun 15, 2026
CVE-2026-27089
7.5 HIGH

Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.

Jun 15, 2026
CVE-2026-27053
9.8 CRITICAL

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

Jun 15, 2026
CVE-2026-25440
5.3 MEDIUM

Unauthenticated Broken Access Control in Essential Addons for Elementor < 6.6.0 versions.

Jun 15, 2026
CVE-2026-25425
7.5 HIGH

Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.

Jun 15, 2026
CVE-2026-24637
8.5 HIGH

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

Jun 15, 2026
CVE-2026-23970
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.

Jun 15, 2026
CVE-2025-69332
6.5 MEDIUM

Subscriber Broken Access Control in Bookify <= 1.1.1 versions.

Jun 15, 2026
CVE-2025-68872
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.

Jun 15, 2026
CVE-2025-68851
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.

Jun 15, 2026
CVE-2025-68840
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.

Jun 15, 2026
CVE-2025-68049
6.3 MEDIUM

Subscriber Broken Access Control in bunny.net <= 2.3.6 versions.

Jun 15, 2026
CVE-2025-60175
4.4 MEDIUM

Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions.

Jun 15, 2026
CVE-2025-59133
7.5 HIGH

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

Jun 15, 2026
CVE-2026-53705
7.6 HIGH

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size …

Jun 15, 2026
CVE-2026-53704
7.1 HIGH

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the …

Jun 15, 2026
CVE-2026-53703
7.1 HIGH

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure …

Jun 15, 2026
CVE-2026-52722
7.1 HIGH

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, …

Jun 15, 2026
CVE-2026-52721
5.3 MEDIUM

Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element …

Jun 15, 2026
CVE-2026-52720
8.8 HIGH

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a …

Jun 15, 2026
CVE-2026-52719
7.1 HIGH

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream …

Jun 15, 2026
CVE-2026-52718
6.5 MEDIUM

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API …

Jun 15, 2026
CVE-2026-50892
6.5 MEDIUM

Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material …

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.