Browse 341,909+ CVEs from NVD & CNNVD with AI-powered analysis, AI-generated PoCs, KEV/EPSS tracking, and daily security intelligence. Filter by vendor, product, severity, or CWE.
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-50972 | WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php | WooCommerce | WooCommerce | Critical | 9.8 | 2026-06-20 13:37:00 | Deep Dive |
| CVE-2020-37255 | WordPress Time Capsule Plugin 1.21.16 Authentication Bypass | Wptimecapsule | Time Capsule Plugin | High | 7.5 | 2026-06-20 13:36:53 | Deep Dive |
| CVE-2019-25763 | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 Authentication Bypass | Ultimatebeaver | Ultimate Addons for Beaver Builder | Critical | 9.8 | 2026-06-20 13:36:33 | Deep Dive |
| CVE-2026-12673 | Liquidfiles 4.2.12以下版本存在越权漏洞 | liquidfiles | liquidfiles | - | - | 2026-06-20 12:36:23 | Deep Dive |
| CVE-2026-48908 | Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.12 | joomshaper.net | SP Page Builder extension for Joomla | - | - | 2026-06-20 11:57:01 | Deep Dive |
| CVE-2026-48939 | Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15 | icagenda.com | iCagenda extension for Joomla | - | - | 2026-06-20 11:56:51 | Deep Dive |
| CVE-2026-48909 | Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4 | joomshaper.net | SP LMS extension for Joomla | - | - | 2026-06-20 11:56:47 | Deep Dive |
| CVE-2026-11911 | Simple File List <= 6.3.7 - Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter | eemitch | Simple File List | High | 7.5 | 2026-06-20 08:29:49 | Deep Dive |
| CVE-2026-12119 | Simple File List <= 6.3.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute | eemitch | Simple File List | Medium | 6.5 | 2026-06-20 08:29:49 | Deep Dive |
| CVE-2026-11912 | Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action | eemitch | Simple File List | High | 7.5 | 2026-06-20 08:29:48 | Deep Dive |
| CVE-2026-9843 | Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value | crmperks | Database for Contact Form 7, WPforms, Elementor forms | High | 8.1 | 2026-06-20 01:27:23 | Deep Dive |
| CVE-2026-9265 | Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path | JONASBN | Crypt::OpenSSL::PKCS12 | - | - | 2026-06-20 00:46:08 | Deep Dive |
| CVE-2026-56216 | Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey | Capgo | Capgo | High | 8.8 | 2026-06-20 00:14:39 | Deep Dive |
| CVE-2026-56215 | Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning | Capgo | Capgo | High | 8.3 | 2026-06-20 00:14:38 | Deep Dive |
| CVE-2026-56214 | Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC | Capgo | Capgo | High | 7.5 | 2026-06-20 00:14:38 | Deep Dive |
| CVE-2026-56213 | Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC | Capgo | Capgo | Medium | 5.3 | 2026-06-20 00:14:37 | Deep Dive |
| CVE-2026-56212 | Capgo - Improper 2FA Enforcement Logic via Team Security Settings | Capgo | Capgo | Low | 3.8 | 2026-06-20 00:14:36 | Deep Dive |
| CVE-2026-11551 | Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover | wpmudev | Branda – White Label & Branding, Free Login Page Customizer | Critical | 9.8 | 2026-06-19 23:29:22 | Deep Dive |
| CVE-2026-56082 | Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RPC | Cap-go | capgo | High | 7.5 | 2026-06-19 21:39:22 | Deep Dive |
| CVE-2026-56081 | Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email | Cap-go | capgo | Critical | 9.1 | 2026-06-19 21:39:21 | Deep Dive |