CVE Database

135497+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-56071
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions.

Jun 25, 2026
CVE-2026-56054
7.7 HIGH

Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.

Jun 25, 2026
CVE-2026-56053
8.8 HIGH

Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions.

Jun 25, 2026
CVE-2026-56051
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.

Jun 25, 2026
CVE-2026-56050
6.5 MEDIUM

Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PPOM for WooCommerce: from n/a …

Jun 25, 2026
CVE-2026-56049
8.5 HIGH

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

Jun 25, 2026
CVE-2026-56042
7.1 HIGH

Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions.

Jun 25, 2026
CVE-2026-56023
5.4 MEDIUM

Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions.

Jun 25, 2026
CVE-2026-56014
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions.

Jun 25, 2026
CVE-2026-56013
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

Jun 25, 2026
CVE-2026-56006
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.

Jun 25, 2026
CVE-2026-56005
7.1 HIGH

Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.

Jun 25, 2026
CVE-2026-54849
9.3 CRITICAL

Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions.

Jun 25, 2026
CVE-2026-54848
8.3 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square …

Jun 25, 2026
CVE-2026-54845
8.1 HIGH

Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions.

Jun 25, 2026
CVE-2026-54844
7.5 HIGH

Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.

Jun 25, 2026
CVE-2026-54843
9.3 CRITICAL

Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.

Jun 25, 2026
CVE-2026-54842
8.1 HIGH

Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Royal MCP: from n/a through 1.4.25.

Jun 25, 2026
CVE-2026-54841
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.

Jun 25, 2026
CVE-2026-54838
8.5 HIGH

Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

Jun 25, 2026
CVE-2026-54836
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows SQL Injection. This issue affects YMC Filter: from …

Jun 25, 2026
CVE-2026-54830
7.5 HIGH

Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.

Jun 25, 2026
CVE-2026-54829
7.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. …

Jun 25, 2026
CVE-2026-54828
7.5 HIGH

Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.

Jun 25, 2026
CVE-2026-54823
9.9 CRITICAL

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

Jun 25, 2026
CVE-2026-54822
8.5 HIGH

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

Jun 25, 2026
CVE-2026-54821
7.4 HIGH

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

Jun 25, 2026
CVE-2026-52690
5.9 MEDIUM

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server …

Jun 25, 2026
CVE-2026-4526
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logic and terminate the process. These messages must come …

Jun 25, 2026
CVE-2026-49506
7.2 HIGH

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A …

Jun 25, 2026
CVE-2026-47154
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating interval entries and terminate the process. These messages must come …

Jun 25, 2026
CVE-2026-47153
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-zero fault. This command must come from a …

Jun 25, 2026
CVE-2026-47152
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a …

Jun 25, 2026
CVE-2026-47151
7.1 HIGH

In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock schedule state. The size and location of this data is …

Jun 25, 2026
CVE-2026-47150
7.1 HIGH

In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write and terminate the process. The size and location of …

Jun 25, 2026
CVE-2026-47149
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table reads and terminate the process. These messages must come …

Jun 25, 2026
CVE-2026-47148
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the message payload and terminate the process. These messages …

Jun 25, 2026
CVE-2026-47147
7.1 HIGH

In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limited amount of data from RAM is …

Jun 25, 2026
CVE-2026-47146
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that …

Jun 25, 2026
CVE-2026-47145
6.5 MEDIUM

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that …

Jun 25, 2026
CVE-2026-46734
7.3 HIGH

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could …

Jun 25, 2026
CVE-2026-46733
7.8 HIGH

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could …

Jun 25, 2026
CVE-2026-46732
6.7 MEDIUM

Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A …

Jun 25, 2026
CVE-2026-42390
5.3 MEDIUM

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

Jun 25, 2026
CVE-2026-42389
5.3 MEDIUM

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

Jun 25, 2026
CVE-2026-42388
5.9 MEDIUM

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

Jun 25, 2026
CVE-2026-42387
5.9 MEDIUM

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input …

Jun 25, 2026
CVE-2026-41120
9.8 CRITICAL

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker …

Jun 25, 2026
CVE-2026-40012
5.3 MEDIUM

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

Jun 25, 2026
CVE-2026-2815

Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

Jun 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.