CVE Database

115314+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9057
8.2 HIGH

A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio …

May 20, 2026
CVE-2026-9056
5.4 MEDIUM

A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload …

May 20, 2026
CVE-2026-7522
8.8 HIGH

The Advanced Database Cleaner – Premium plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.0 via the 'template' …

May 20, 2026
CVE-2026-5075
4.3 MEDIUM

The All in One SEO plugin for WordPress is vulnerable to Sensitive Information Exposure via 'internalOptions' localized script data in versions up to, and including, …

May 20, 2026
CVE-2026-9010
7.5 HIGH

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3 due …

May 20, 2026
CVE-2026-9003
7.5 HIGH

E-LAN Hybrid Recording System developed by TONNET has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

May 20, 2026
CVE-2026-7637
9.8 CRITICAL

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the …

May 20, 2026
CVE-2026-7460

mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue …

May 20, 2026
CVE-2026-24215
5.7 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability …

May 20, 2026
CVE-2026-24214
8.0 HIGH

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an integer overflow. A successful exploit of this vulnerability …

May 20, 2026
CVE-2026-24213
8.0 HIGH

NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability …

May 20, 2026
CVE-2026-24210
7.5 HIGH

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to denial …

May 20, 2026
CVE-2026-24209
7.5 HIGH

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to …

May 20, 2026
CVE-2026-24208
5.3 MEDIUM

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to …

May 20, 2026
CVE-2026-24207
9.8 CRITICAL

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code …

May 20, 2026
CVE-2026-24206
7.3 HIGH

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation …

May 20, 2026
CVE-2026-24163
7.5 HIGH

NVIDIA TRT-LLM for any platform contains a vulnerability in RPC testing, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability …

May 20, 2026
CVE-2026-24160
5.5 MEDIUM

NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit …

May 20, 2026
CVE-2026-24142
6.3 MEDIUM

NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data …

May 20, 2026
CVE-2025-33255
7.5 HIGH

NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserialization. A successful exploit of this vulnerability …

May 20, 2026
CVE-2025-15369
5.3 MEDIUM

The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

May 20, 2026
CVE-2026-8685
6.5 MEDIUM

The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. …

May 20, 2026
CVE-2026-8627
6.1 MEDIUM

The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is …

May 20, 2026
CVE-2026-8626
6.1 MEDIUM

The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient …

May 20, 2026
CVE-2026-8624
6.1 MEDIUM

The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 …

May 20, 2026
CVE-2026-8610
4.3 MEDIUM

The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to …

May 20, 2026
CVE-2026-8424
4.3 MEDIUM

The Remove Yellow BGBOX plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to …

May 20, 2026
CVE-2026-8423
4.3 MEDIUM

The JaviBola Custom Theme Test plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.5. This is due …

May 20, 2026
CVE-2026-8420
6.1 MEDIUM

The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to …

May 20, 2026
CVE-2026-8419
4.3 MEDIUM

The Amazon Scraper plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing …

May 20, 2026
CVE-2026-8418
4.3 MEDIUM

The Games Catalog plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.0. This is due to missing or …

May 20, 2026
CVE-2026-8038
6.4 MEDIUM

The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions …

May 20, 2026
CVE-2026-7472
4.9 MEDIUM

The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and …

May 20, 2026
CVE-2026-7467
8.8 HIGH

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to …

May 20, 2026
CVE-2026-7462
6.1 MEDIUM

The VatanSMS WP SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `page` parameter in all versions up to, and including, 1.01. …

May 20, 2026
CVE-2026-7284
9.8 CRITICAL

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to privilege escalation via user registration in all versions up …

May 20, 2026
CVE-2026-6555
9.8 CRITICAL

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an …

May 20, 2026
CVE-2026-6549
6.4 MEDIUM

The Logo Manager For Enamad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute of the `vc_enamad_namad`, `vc_enamad_shamed`, and `vc_enamad_custom` shortcodes …

May 20, 2026
CVE-2026-6456
8.8 HIGH

The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.2. This is due to the `rememberLogin` …

May 20, 2026
CVE-2026-6452
4.3 MEDIUM

The Bigfishgames Syndicate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing …

May 20, 2026
CVE-2026-6404
4.4 MEDIUM

The Anomify AI – Anomaly Detection and Alerting plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'anomify_api_key' parameter in versions up to …

May 20, 2026
CVE-2026-6401
4.3 MEDIUM

The Bottom Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 0.1.7. This is due to missing …

May 20, 2026
CVE-2026-6400
4.3 MEDIUM

The Child Height Predictor by Ostheimer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to and including 1.3. This is …

May 20, 2026
CVE-2026-6399
4.4 MEDIUM

The General Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.1.0. This is due to the use …

May 20, 2026
CVE-2026-6397
6.4 MEDIUM

The Sticky plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `cvmh-sticky` shortcode `readmoretext` attribute in versions up to and including 2.5.6. This …

May 20, 2026
CVE-2026-6395
6.1 MEDIUM

The Word 2 Cash plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Stored Cross-Site Scripting in versions up to and including 0.9.2. …

May 20, 2026
CVE-2026-6394
5.4 MEDIUM

The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions …

May 20, 2026
CVE-2026-6391
6.1 MEDIUM

The Sentence To SEO (keywords, description and tags) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. …

May 20, 2026
CVE-2026-6072
6.5 MEDIUM

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up …

May 20, 2026
CVE-2026-5293
6.4 MEDIUM

The 診断ジェネレータ作成プラグイン (Diagnosis Generator) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'js' parameter in versions up to and including 1.4.16. This …

May 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.