CVE search
370,413 resultsCVE-2026-47262MEDIUMcontainerd image-triggered runtime DoS via unbounded group parsingEPSS 0.3%CVE-2026-57737MEDIUMWordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.16 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-57736HIGHWordPress HubSpot plugin <= 11.3.51 - Sensitive Data Exposure vulnerabilityEPSS 0.2%CVE-2026-46680HIGHcontainerd user ID handling bypass allows runAsNonRoot evasionEPSS 0.2%CVE-2026-58521MEDIUMSQLi in Cargo extension via year range filterEPSS 0.3%CVE-2026-49091HIGHImproper Output Neutralization for Logs in Kibana Leading to Log InjectionEPSS 0.2%CVE-2026-49090MEDIUMUncontrolled Resource Consumption in Elasticsearch Leading to Denial of ServiceEPSS 0.3%CVE-2026-58520MEDIUMUrlShortener defaults to ineffective validation open to third-party redirectsEPSS 0.2%CVE-2026-5051MEDIUMAudit Log Plugin Directory Guard Bypass via Legacy path OptionEPSS 0.3%CVE-2026-57723HIGHWordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerabilityEPSS 0.1%CVE-2026-57722MEDIUMWordPress Enable Media Replace plugin <= 4.2.1 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.1%CVE-2026-54428HIGHApache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACKEPSS 0.6%CVE-2026-54399HIGHApache HttpComponents Core: Unbounded HTTP Header/Line Length in Default ConfigurationEPSS 0.6%CVE-2026-49088MEDIUMInsertion of Sensitive Information into Log File in Kibana Leading to Information DisclosureEPSS 0.2%CVE-2026-57721MEDIUMWordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-57720MEDIUMWordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-12480MEDIUMArbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/kerasEPSS 0.1%CVE-2026-57516HIGHRay < 2.56.0 Unsafe Deserialization RCE via WebDataset ReaderEPSS 0.6%CVE-2026-49087MEDIUMAllocation of Resources Without Limits or Throttling in Kibana Leading to Denial of ServiceEPSS 0.3%CVE-2026-56152MEDIUMIncorrect Authorization in Elastic Defend Leading to Information DisclosureEPSS 0.2%