CVE search
400,919 resultsCVE-2026-103885—Apache Directory LDAP API: Denial of service via crafted telephone number valuesEPSS —CVE-2026-103877—Apache Directory LDAP API: Unsafe loading of Java code from LDAP schema elementsEPSS —CVE-2026-59662MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-103880—Apache Directory LDAP API: Denial of service via excessive bcrypt cost factor in stored passwordsEPSS —CVE-2026-59664MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-103878—Apache Directory LDAP API: Injection of plaintext responses during StartTLSEPSS —CVE-2026-59663MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-104403MEDIUMWordPress LearnPress plugin <= 4.4.9 - Insecure Direct Object References (IDOR) vulnerabilityEPSS —CVE-2026-95662MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-103552HIGHApache Directory LDAP API: A unbound client can send a deeply nested search filter that overflows the stack in the server's decoderEPSS —CVE-2026-59661MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-59660MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-59659MEDIUMMultiple vulnerabilities in the Repasat applicationEPSS —CVE-2026-94180MEDIUMWordPress Advanced Ads plugin <= 2.0.26 - Sensitive Data Exposure vulnerabilityEPSS —CVE-2026-94639HIGHApache Thrift: Java `TSaslNonblockingServer`: residual of CVE-2026-61373 (thread-death black hole + no cross-connection budget)EPSS —CVE-2026-94405MEDIUMWordPress Download Manager plugin <= 3.3.71 - Sensitive Data Exposure vulnerabilityEPSS —CVE-2026-97652MEDIUMWP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter KeyEPSS —CVE-2026-85492MEDIUMAll in One SEO <= 5.0.1.1 - Reflected DOM-Based Cross-Site Scripting via URL PathnameEPSS —CVE-2026-87920HIGHW3 Total Cache <= 2.10.6 - Unauthenticated Stored Cross-Site Scripting via Comment ContentEPSS —CVE-2026-94541CRITICALWPMobile.App <= 11.82 - Unauthenticated Admin Account Takeover via 'wpapp_category[]' ParameterEPSS —