CVE Database

132006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-17037
7.2 HIGH

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘comment’ parameter in all …

Sep 11, 2026
CVE-2026-87727
6.5 MEDIUM

a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected …

Sep 11, 2026
CVE-2026-80469
8.3 HIGH

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the …

Sep 11, 2026
CVE-2026-19486

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an …

Sep 11, 2026
CVE-2025-15679

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

Sep 11, 2026
CVE-2026-89179
4.3 MEDIUM

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept …

Sep 11, 2026
CVE-2026-89178
8.8 HIGH

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher …

Sep 11, 2026
CVE-2026-89177
8.8 HIGH

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated …

Sep 11, 2026
CVE-2026-89176
8.8 HIGH

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student …

Sep 11, 2026
CVE-2026-89175
5.3 MEDIUM

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and …

Sep 11, 2026
CVE-2026-89174
7.5 HIGH

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through …

Sep 11, 2026
CVE-2026-89173
5.3 MEDIUM

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting …

Sep 11, 2026
CVE-2026-6642
6.4 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and …

Sep 11, 2026
CVE-2026-6641
6.4 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This …

Sep 11, 2026
CVE-2026-6640
6.4 MEDIUM

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 …

Sep 11, 2026
CVE-2026-87908
7.5 HIGH

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound …

Sep 11, 2026
CVE-2026-86815
5.5 MEDIUM

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing …

Sep 11, 2026
CVE-2026-86812
6.5 MEDIUM

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect …

Sep 11, 2026
CVE-2026-86782
5.5 MEDIUM

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, …

Sep 11, 2026
CVE-2026-86781
5.3 MEDIUM

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download …

Sep 11, 2026
CVE-2026-86780
6.8 MEDIUM

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow …

Sep 11, 2026
CVE-2026-86779
2.7 LOW

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users …

Sep 11, 2026
CVE-2026-85678
6.8 MEDIUM

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the …

Sep 11, 2026
CVE-2026-85677
8.8 HIGH

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant …

Sep 11, 2026
CVE-2026-83546
6.8 MEDIUM

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access …

Sep 11, 2026
CVE-2026-83545
6.8 MEDIUM

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level …

Sep 11, 2026
CVE-2026-82305
5.3 MEDIUM

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to …

Sep 11, 2026
CVE-2026-74925
7.2 HIGH

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant …

Sep 11, 2026
CVE-2026-73785
7.5 HIGH

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

Sep 11, 2026
CVE-2026-73784
8.8 HIGH

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

Sep 11, 2026
CVE-2026-14566
4.3 MEDIUM

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, …

Sep 11, 2026
CVE-2026-14565
5.4 MEDIUM

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the …

Sep 11, 2026
CVE-2026-14563
9.8 CRITICAL

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, …

Sep 11, 2026
CVE-2026-14562
5.3 MEDIUM

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, …

Sep 11, 2026
CVE-2026-14560
10.0 CRITICAL

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated …

Sep 11, 2026
CVE-2026-14559
9.8 CRITICAL

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, …

Sep 11, 2026
CVE-2026-13326

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure …

Sep 11, 2026
CVE-2025-15695
3.5 LOW

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, …

Sep 11, 2026
CVE-2026-89169

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

Sep 11, 2026
CVE-2026-89162
2.9 LOW

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already …

Sep 11, 2026
CVE-2026-89060
7.7 HIGH

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside …

Sep 11, 2026
CVE-2026-8778
9.8 CRITICAL

The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing …

Sep 11, 2026
CVE-2026-89161
7.4 HIGH

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

Sep 11, 2026
CVE-2026-89160
3.7 LOW

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

Sep 11, 2026
CVE-2026-89158
6.5 MEDIUM

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

Sep 11, 2026
CVE-2026-89157
5.7 MEDIUM

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

Sep 11, 2026
CVE-2026-89156
2.9 LOW

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

Sep 11, 2026
CVE-2026-84960
6.1 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 …

Sep 11, 2026
CVE-2026-81825
7.2 HIGH

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all …

Sep 11, 2026
CVE-2026-81754
7.2 HIGH

The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in …

Sep 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.