CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-85130

8.8

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative …

WordPress
Details

CVE-2026-85128

7.5

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to …

WordPress
Details

CVE-2025-15697

7.1

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site …

WordPress
Details

CVE-2026-87796

9.8

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due …

WordPress
Details

CVE-2026-50604

4.9

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the …

Acer
Details

CVE-2026-25290

7.8

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

Details

CVE-2026-25284

7.3

Information Disclosure when a pointer is reused after being deallocated.

Information
Details

CVE-2026-25283

8.8

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Details

CVE-2026-25282

7.9

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

Transient
Details
162/9185