VULNERABILITY INTELLIGENCE

CVE index

Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.

NVD data is used under its public data terms. This service is not endorsed or certified by NVD.
17,661 CVE recordsPage 67 of 1178 · EPSS data 2026.08.06
ReviewHigh
CVE-2026-14924

Tablesome Table

The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX actions, allowing unauthenticated users to create new published posts and to overwrite arbitrary existing posts and pages.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14870

Database for Contact Form 7, WPforms, Elementor forms

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

The CVSS severity warrants an early asset and exposure review.
ReviewCritical
CVE-2026-14545

TrueBooker

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated attackers to set an arbitrary password on any account, including an administrator, and take over the site.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-14490

deveasel Demi – One Click Demo Import, Backup & Site Migration

The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 0.0.7. The vulnerability exists because the plugin stores its HMAC signing key and per-step restore token as dotfiles inside a publicly accessible subdirectory of the WordPress uploads folder — without any `.htaccess` or index file protection — and the `demi_restore_step` AJAX handler, registered for unauthenticated callers, explicitly accepts possession of the on-disk signing key as a standalone alternative to WordPress capabi...

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-17524

zip-lib

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-66473

Xendit Xendit Payment

CVE-2026-66473 affects Xendit Xendit Payment. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65446

WP Chill Kali Forms

CVE-2026-65446 affects WP Chill Kali Forms. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65443

WP Media BackWPup

CVE-2026-65443 affects WP Media BackWPup. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65442

Subtle Web Inc FormCraft

CVE-2026-65442 affects Subtle Web Inc FormCraft. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65441

Nexcess GiveWP

CVE-2026-65441 affects Nexcess GiveWP. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.
ReviewHigh
CVE-2026-65440

Roxnor GetGenie

CVE-2026-65440 affects Roxnor GetGenie. Review the CVSS score, exploitation signals, affected versions, remediation status, and linked source material before making a change.

The CVSS severity warrants an early asset and exposure review.