CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-39534
7.5 HIGH

Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.

Jun 15, 2026
CVE-2026-39533
7.5 HIGH

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.

Jun 15, 2026
CVE-2026-39532
8.8 HIGH

Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions.

Jun 15, 2026
CVE-2026-39524
7.5 HIGH

Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.

Jun 15, 2026
CVE-2026-39518
7.1 HIGH

Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.

Jun 15, 2026
CVE-2026-39514
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Paid Member Subscriptions <= 2.17.3 versions.

Jun 15, 2026
CVE-2026-39513
7.5 HIGH

Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.

Jun 15, 2026
CVE-2026-39507
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Social Slider Feed <= 2.3.2 versions.

Jun 15, 2026
CVE-2026-39503
7.5 HIGH

Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.

Jun 15, 2026
CVE-2026-39499
7.2 HIGH

Shop manager PHP Object Injection in Advanced Product Fields (Product Addons) for WooCommerce <= 1.6.19 versions.

Jun 15, 2026
CVE-2026-39498
7.2 HIGH

Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.

Jun 15, 2026
CVE-2026-39481
7.2 HIGH

Author PHP Object Injection in Modula Image Gallery <= 2.14.18 versions.

Jun 15, 2026
CVE-2026-39480
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.

Jun 15, 2026
CVE-2026-39478
8.8 HIGH

Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions.

Jun 15, 2026
CVE-2026-39474
8.8 HIGH

Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions.

Jun 15, 2026
CVE-2026-39472
7.2 HIGH

Shop manager PHP Object Injection in WooCommerce PDF Invoices & Packing Slips < 5.9.0 versions.

Jun 15, 2026
CVE-2026-39471
7.2 HIGH

Author PHP Object Injection in ShortPixel Image Optimizer <= 6.4.3 versions.

Jun 15, 2026
CVE-2026-39470
7.2 HIGH

Shop manager Privilege Escalation in WooCommerce Cart Abandonment Recovery < 2.1.0 versions.

Jun 15, 2026
CVE-2026-39463
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions.

Jun 15, 2026
CVE-2026-39450
7.1 HIGH

Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.

Jun 15, 2026
CVE-2026-39449
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Contact Form to Any API <= 3.0.3 versions.

Jun 15, 2026
CVE-2026-39447
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.10.6 versions.

Jun 15, 2026
CVE-2026-39435
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.

Jun 15, 2026
CVE-2026-39434
7.2 HIGH

Shop manager PHP Object Injection in CTX Feed <= 6.6.26 versions.

Jun 15, 2026
CVE-2026-34902
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions.

Jun 15, 2026
CVE-2026-34900
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.14.2 versions.

Jun 15, 2026
CVE-2026-34898
7.5 HIGH

Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.

Jun 15, 2026
CVE-2026-34891
7.5 HIGH

Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.

Jun 15, 2026
CVE-2026-34886
7.5 HIGH

Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.

Jun 15, 2026
CVE-2026-27407
7.2 HIGH

Editor Privilege Escalation in AI Engine <= 3.4.9 versions.

Jun 15, 2026
CVE-2026-27333
8.1 HIGH

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.

Jun 15, 2026
CVE-2026-27089
7.5 HIGH

Unauthenticated Bypass Vulnerability in WpTravelly <= 2.1.7 versions.

Jun 15, 2026
CVE-2026-25425
7.5 HIGH

Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.

Jun 15, 2026
CVE-2026-24637
8.5 HIGH

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

Jun 15, 2026
CVE-2026-23970
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Redirection for Contact Form 7 <= 3.2.8 versions.

Jun 15, 2026
CVE-2025-68872
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions.

Jun 15, 2026
CVE-2025-68851
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.

Jun 15, 2026
CVE-2025-68840
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions.

Jun 15, 2026
CVE-2025-59133
7.5 HIGH

Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.

Jun 15, 2026
CVE-2026-53705
7.6 HIGH

A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size …

Jun 15, 2026
CVE-2026-53704
7.1 HIGH

A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the …

Jun 15, 2026
CVE-2026-53703
7.1 HIGH

A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure …

Jun 15, 2026
CVE-2026-52722
7.1 HIGH

A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, …

Jun 15, 2026
CVE-2026-52720
8.8 HIGH

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a …

Jun 15, 2026
CVE-2026-52719
7.1 HIGH

An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream …

Jun 15, 2026
CVE-2026-50891
8.1 HIGH

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

Jun 15, 2026
CVE-2026-50889
7.5 HIGH

An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a …

Jun 15, 2026
CVE-2026-50888
8.1 HIGH

An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying …

Jun 15, 2026
CVE-2026-50885
7.5 HIGH

Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.

Jun 15, 2026
CVE-2026-50884
8.8 HIGH

Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.