CVE search
369,558 resultsCVE-2026-8926CRITICALpassword leak with netrc and user in URLEPSS 0.6%CVE-2026-8925CRITICALSASL double-freeEPSS 1.1%CVE-2026-8924CRITICALtrailing dot domain super cookieEPSS 0.6%CVE-2026-8458MEDIUMwrong reuse for different servicesEPSS 0.5%CVE-2026-8286HIGHwrong STARTTLS connection reuseEPSS 0.5%CVE-2026-12064HIGHproto-default skips SSH verificationEPSS 0.6%CVE-2026-11856CRITICALcross-origin Digest auth state leakEPSS 1.1%CVE-2026-11586HIGHWS Auto-PONG memory exhaustionEPSS 0.9%CVE-2026-11564CRITICALNative CA trust persistEPSS 0.6%CVE-2026-11352HIGHQUIC zero-length UDP datagrams busy-loopEPSS 1.0%CVE-2026-10536CRITICALHTTP/2 stream-dependency tree UAFEPSS 0.9%CVE-2026-4967HIGHIn IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additionalEPSS 0.4%CVE-2026-9180MEDIUMMotoPress Appointment Booking <= 2.4.4 - Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' ParameterEPSS 0.3%CVE-2026-8892MEDIUMCM Business Directory <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta FieldsEPSS 0.2%CVE-2026-9626MEDIUMJSON API User <= 4.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' ParameterEPSS 0.2%CVE-2026-11397MEDIUMWP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' ParameterEPSS 0.2%CVE-2026-9725CRITICALPrintcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File DeletionEPSS 0.7%CVE-2026-13040HIGHNEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' ParameterEPSS 0.3%CVE-2026-8489MEDIUMUltimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile FieldEPSS 0.2%CVE-2026-14352HIGHAR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' ParameterEPSS 0.5%