CVE search
400,992 resultsCVE-2026-63575HIGHPKCS#12 key derivation loops about 2^32 times on a zero or negative iteration countEPSS 0.2%CVE-2026-63574HIGHUnbounded allocation from OpenPGP signature and user attribute subpacket lengthsEPSS 0.3%CVE-2026-63573HIGHBleichenbacher padding oracle in CMS RSA PKCS#1 v1.5 key-transport unwrapEPSS 0.3%CVE-2026-63572HIGHUnbounded MAC and bag-decryption iteration counts when loading PKCS#12 filesEPSS 0.3%CVE-2026-63571HIGHAttribute certificate path validation does not verify the attribute certificate's signatureEPSS 0.2%CVE-2026-63570HIGHPkcs12Store.GetCertificateChain loops forever on cyclic issuer linksEPSS 0.2%CVE-2026-63569CRITICALMTI/A0 DHAgreement does not validate the peer's ephemeral valueEPSS 0.4%CVE-2026-63568HIGHUnbounded CMP/CRMF password-based MAC iteration count allows CPU exhaustionEPSS 0.3%CVE-2026-63567HIGHIesEngine block-cipher mode checks padding before MAC (CBC padding oracle)EPSS 0.5%CVE-2026-63566HIGHDTLS handshake reassembler allocates buffer from unchecked 24-bit lengthEPSS 0.4%CVE-2026-97219MEDIUMMStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' ParameterEPSS 0.2%CVE-2026-92924MEDIUMUnlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via get_addon_output_dataEPSS 0.2%CVE-2026-91020MEDIUMWebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amountEPSS 0.3%CVE-2026-90987MEDIUMEasy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulation via Client-Supplied PriceEPSS 0.2%CVE-2026-90952MEDIUMWP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass via REST APIEPSS 0.2%CVE-2026-85005MEDIUMPopup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing AuthorizationEPSS 0.2%CVE-2026-84740MEDIUMThe Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'view_data' ParameterEPSS 0.2%CVE-2026-79618MEDIUMWP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated FormEPSS 0.2%CVE-2026-1661MEDIUMWP Mail Logging < 1.17.0 - Unauthenticated HTML InjectionEPSS 0.2%CVE-2026-13413MEDIUMCMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Login URL MatchEPSS 0.2%