CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-63030CRITICAL | WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code ExecutionWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | CVSS9.8v3.1 | EPSS95.6% | PoCs80 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-60137MEDIUM | WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryWordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CWE-89Jul 17, 2026 | CVSS5.9v3.1 | EPSS73.1% | PoCs53 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |