CVE search

369,825 results
CVE-2026-8892MEDIUMCM Business Directory <= 1.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta FieldsEPSS 0.2%CVE-2026-9626MEDIUMJSON API User <= 4.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' ParameterEPSS 0.2%CVE-2026-11397MEDIUMWP Import Export Lite <= 3.9.30 - Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' ParameterEPSS 0.2%CVE-2026-9725CRITICALPrintcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File DeletionEPSS 0.7%CVE-2026-13040HIGHNEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via 'real_val__' ParameterEPSS 0.3%CVE-2026-8489MEDIUMUltimate Member <= 2.11.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile FieldEPSS 0.2%CVE-2026-14352HIGHAR for WooCommerce <= 8.40 - Unauthenticated Path Traversal to Arbitrary File Read via 'file' ParameterEPSS 0.5%CVE-2026-12557MEDIUMNinja Forms - File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST EndpointsEPSS 0.2%CVE-2022-4989HIGH** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to acceEPSS 0.1%CVE-2022-4990HIGH** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypaEPSS 0.1%CVE-2026-8921HIGHExternal Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM priviEPSS 0.1%CVE-2026-12960MEDIUMAn Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device toEPSS 0.1%CVE-2026-14327HIGHAR for WordPress <= 8.40 - Unauthenticated Arbitrary File Read via 'file' ParameterEPSS 0.5%CVE-2026-12731MEDIUMweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block AttributesEPSS 0.2%CVE-2026-12920MEDIUMCookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Administrator+) SQL Injection via 's' ParameterEPSS 0.3%CVE-2026-12729MEDIUMweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX ActionEPSS 0.2%CVE-2026-12734MEDIUMweDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block AttributeEPSS 0.2%CVE-2026-54477MEDIUMGardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting SyntaxEPSS 0.2%CVE-2026-55726MEDIUMGardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.4%CVE-2026-13768CRITICALGardyn IoT Hub Use of Hard-coded CredentialsEPSS 0.6%