CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-5802
5.3 MEDIUM

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing …

Sep 15, 2026
CVE-2026-91826
4.4 MEDIUM

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects …

Sep 15, 2026
CVE-2026-91091
4.3 MEDIUM

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. …

Sep 15, 2026
CVE-2026-91089
6.3 MEDIUM

A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. …

Sep 15, 2026
CVE-2026-91088
4.8 MEDIUM

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. …

Sep 15, 2026
CVE-2026-91086
6.3 MEDIUM

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the …

Sep 15, 2026
CVE-2026-91005
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture …

Sep 15, 2026
CVE-2026-89141
6.5 MEDIUM

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Sep 15, 2026
CVE-2026-18063
6.4 MEDIUM

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due …

Sep 15, 2026
CVE-2026-15402
6.4 MEDIUM

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter …

Sep 15, 2026
CVE-2026-91002
5.3 MEDIUM

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist …

Sep 15, 2026
CVE-2026-81320
5.5 MEDIUM

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, …

Sep 15, 2026
CVE-2026-81303
6.3 MEDIUM

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into …

Sep 15, 2026
CVE-2026-18232
5.3 MEDIUM

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of …

Sep 15, 2026
CVE-2026-17495
5.9 MEDIUM

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to …

Sep 15, 2026
CVE-2026-16593
6.8 MEDIUM

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated …

Sep 15, 2026
CVE-2026-15758
5.3 MEDIUM

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Sep 15, 2026
CVE-2026-90881
5.3 MEDIUM

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. …

Sep 15, 2026
CVE-2026-90878
4.3 MEDIUM

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. …

Sep 15, 2026
CVE-2026-90857
6.3 MEDIUM

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile …

Sep 15, 2026
CVE-2026-91774
4.3 MEDIUM

Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to read full team records. Attackers can supply a …

Sep 15, 2026
CVE-2026-91773
4.3 MEDIUM

Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they …

Sep 15, 2026
CVE-2026-91772
6.1 MEDIUM

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious …

Sep 15, 2026
CVE-2026-91770
6.5 MEDIUM

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute …

Sep 15, 2026
CVE-2026-90851
6.3 MEDIUM

A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument …

Sep 15, 2026
CVE-2026-90848
4.3 MEDIUM

A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of …

Sep 15, 2026
CVE-2026-91750
6.5 MEDIUM

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial …

Sep 15, 2026
CVE-2026-85657
5.4 MEDIUM

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Sep 15, 2026
CVE-2026-85575
6.4 MEDIUM

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored …

Sep 15, 2026
CVE-2026-91201
5.4 MEDIUM

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session …

Sep 14, 2026
CVE-2026-91199
5.0 MEDIUM

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved …

Sep 14, 2026
CVE-2026-91198
5.3 MEDIUM

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge …

Sep 14, 2026
CVE-2026-91197
6.5 MEDIUM

Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. …

Sep 14, 2026
CVE-2026-90831
5.3 MEDIUM

A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. …

Sep 14, 2026
CVE-2026-90830
5.3 MEDIUM

A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The …

Sep 14, 2026
CVE-2026-90829
5.3 MEDIUM

A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. …

Sep 14, 2026
CVE-2026-81900
6.1 MEDIUM

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping …

Sep 14, 2026
CVE-2026-14986
6.8 MEDIUM

The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size …

Sep 14, 2026
CVE-2026-91181
6.5 MEDIUM

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams …

Sep 14, 2026
CVE-2026-91146
6.1 MEDIUM

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. …

Sep 14, 2026
CVE-2026-90828
5.3 MEDIUM

A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan …

Sep 14, 2026
CVE-2026-76081
5.5 MEDIUM

ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted …

Sep 14, 2026
CVE-2026-73449
5.9 MEDIUM

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an …

Sep 14, 2026
CVE-2026-13265
6.8 MEDIUM

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 …

Sep 14, 2026
CVE-2026-12759
6.5 MEDIUM

IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.

Sep 14, 2026
CVE-2026-12758
5.4 MEDIUM

IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.

Sep 14, 2026
CVE-2026-90820
4.3 MEDIUM

A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to …

Sep 14, 2026
CVE-2026-90818
4.3 MEDIUM

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browser Network Configuration. …

Sep 14, 2026
CVE-2026-86924
5.5 MEDIUM

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, …

Sep 14, 2026
CVE-2026-86911
5.5 MEDIUM

This issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27. A malicious app may be able to bypass …

Sep 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.