CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-12317
7.5 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

Jun 16, 2026
CVE-2026-12314
7.5 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12312
7.5 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12310
7.5 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12305
7.5 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12290
8.1 HIGH

Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-12289
8.8 HIGH

Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

Jun 16, 2026
CVE-2026-8442
8.1 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 12.6.8. This is due to …

Jun 16, 2026
CVE-2026-8176
7.5 HIGH

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and …

Jun 16, 2026
CVE-2026-5416
8.8 HIGH

Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in …

Jun 16, 2026
CVE-2026-54198
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions.

Jun 16, 2026
CVE-2026-54191
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions.

Jun 16, 2026
CVE-2026-52712
7.6 HIGH

Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions.

Jun 16, 2026
CVE-2026-52711
7.5 HIGH

Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions.

Jun 16, 2026
CVE-2026-39581
8.5 HIGH

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

Jun 16, 2026
CVE-2026-39490
7.5 HIGH

Unauthenticated Broken Access Control in JupiterX Core <= 4.14.1 versions.

Jun 16, 2026
CVE-2026-39437
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Min Max Step Quantity Limits Manager for WooCommerce <= 5.2.2 versions.

Jun 16, 2026
CVE-2025-68045
7.5 HIGH

Unauthenticated Broken Access Control in WP Event SOlution <= 4.1.12 versions.

Jun 16, 2026
CVE-2026-8444
8.8 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of the wpfb_find_reviews AJAX action in versions up …

Jun 16, 2026
CVE-2026-8443
8.8 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in …

Jun 16, 2026
CVE-2026-6933
8.8 HIGH

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is …

Jun 16, 2026
CVE-2026-7273
8.8 HIGH

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the …

Jun 16, 2026
CVE-2026-12161
8.8 HIGH

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify …

Jun 16, 2026
CVE-2026-48723
7.8 HIGH

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via …

Jun 15, 2026
CVE-2026-48017
8.8 HIGH

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into …

Jun 15, 2026
CVE-2026-52702
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

Jun 15, 2026
CVE-2026-52700
8.5 HIGH

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

Jun 15, 2026
CVE-2026-52699
7.5 HIGH

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

Jun 15, 2026
CVE-2026-52697
8.5 HIGH

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

Jun 15, 2026
CVE-2026-52695
7.5 HIGH

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

Jun 15, 2026
CVE-2026-52694
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

Jun 15, 2026
CVE-2026-52692
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

Jun 15, 2026
CVE-2026-49780
8.8 HIGH

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

Jun 15, 2026
CVE-2026-49112
7.5 HIGH

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

Jun 15, 2026
CVE-2026-49110
7.5 HIGH

Unauthenticated Broken Authentication in Upsell Order Bump Offer for WooCommerce <= 3.1.4 versions.

Jun 15, 2026
CVE-2026-49083
7.5 HIGH

Contributor Privilege Escalation in LatePoint <= 5.5.1 versions.

Jun 15, 2026
CVE-2026-49082
7.4 HIGH

Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.

Jun 15, 2026
CVE-2026-49078
7.5 HIGH

Unauthenticated Other Vulnerability Type in WP Travel Engine <= 6.7.10 versions.

Jun 15, 2026
CVE-2026-49070
7.5 HIGH

Unauthenticated Broken Access Control in Knit Pay <= 9.4.0.0 versions.

Jun 15, 2026
CVE-2026-49068
7.5 HIGH

Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

Jun 15, 2026
CVE-2026-49066
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.

Jun 15, 2026
CVE-2026-49065
8.2 HIGH

Unauthenticated Broken Access Control in Hippoo Mobile App for WooCommerce <= 1.9.5 versions.

Jun 15, 2026
CVE-2026-49063
7.3 HIGH

Unauthenticated Privilege Escalation in Listdom <= 5.5.0 versions.

Jun 15, 2026
CVE-2026-49061
7.5 HIGH

Unauthenticated Arbitrary File Download in WPC Product Options for WooCommerce <= 3.2.1 versions.

Jun 15, 2026
CVE-2026-49056
7.5 HIGH

Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels <= 4.9.4 versions.

Jun 15, 2026
CVE-2026-49055
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.9.7 versions.

Jun 15, 2026
CVE-2026-48970
8.1 HIGH

Unauthenticated Broken Authentication in Really Simple SSL <= 9.5.10 versions.

Jun 15, 2026
CVE-2026-48966
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Funnel Builder by FunnelKit <= 3.15.0.2 versions.

Jun 15, 2026
CVE-2026-48964
8.5 HIGH

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.

Jun 15, 2026
CVE-2026-48889
8.8 HIGH

Subscriber Privilege Escalation in Amelia <= 2.3 versions.

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.