VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 13 of 1178
ReviewCritical
CVE-2026-16300

ChamaWP

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16250

Personal QR Message

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users to upload arbitrary executable PHP files that are directly reachable, leading to remote code execution.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-16060

Insert or Embed Articulate Content into WordPress

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable check that lets an Editor-level user upload a server-executable file into a public directory, resulting in remote code execution on servers configured to execute it.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-15930

Simple Membership

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID to update an account, allowing unauthenticated attackers to overwrite the primary administrator's account data (including the email address) and take over that account through the password reset flow.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14557

SoftMarket — Digital Marketplace

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated attackers to obtain a valid session as any verified user by supplying only that user's ID.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-12965

Super Store Finder WordPress

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2025-15672

ChamaWP

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14682

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), and before bctls-fips 1.0.24.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-13506

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12817

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series) and 2.1.13 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-12802

Legion of the Bouncy Castle Inc. BC-JAVA, BC-LTS-JAVA, BC-FJA

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and 2.1.12 (2.1.X series).

The CVSS severity warrants an early asset and exposure review.