CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61857
3.7 LOW

ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerability caused by missing null check when parsing XMP profiles. Attackers can craft malicious image files with specially …

Jul 11, 2026
CVE-2026-61465
3.3 LOW

ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operations such as -canny. An attacker can supply …

Jul 11, 2026
CVE-2026-61454
5.3 MEDIUM

The Grav Admin2 plugin (getgrav/grav-plugin-admin2) before 2.0.4 embeds a global JavaScript variable window.__GRAV_CONFIG__ in the Admin2 SPA bootstrap page at /grav/admin (and its subroutes). This …

Jul 11, 2026
CVE-2026-61448

Parse Server is affected by a stored cross-site scripting (XSS) vulnerability in versions >= 9.0.0, < 9.10.0-alpha.2 and <= 8.6.83. When an uploaded file's extension …

Jul 11, 2026
CVE-2026-61447
10.0 CRITICAL

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers …

Jul 11, 2026
CVE-2026-61445
9.9 CRITICAL

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM …

Jul 11, 2026
CVE-2026-61442
7.1 HIGH

PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A …

Jul 11, 2026
CVE-2026-61439
7.5 HIGH

PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. …

Jul 11, 2026
CVE-2026-61429
8.5 HIGH

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding …

Jul 11, 2026
CVE-2026-61428
7.3 HIGH

PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted …

Jul 11, 2026
CVE-2026-61426
8.6 HIGH

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call …

Jul 11, 2026
CVE-2026-60090
9.8 CRITICAL

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are …

Jul 11, 2026
CVE-2026-60088
5.5 MEDIUM

PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path …

Jul 11, 2026
CVE-2026-56763
4.8 MEDIUM

Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field names to create objects with __proto__ properties. When …

Jul 11, 2026
CVE-2026-56372
3.3 LOW

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory. An unrecognized magnify:method …

Jul 11, 2026
CVE-2026-56303
7.5 HIGH

Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can …

Jul 11, 2026
CVE-2026-56296
5.3 MEDIUM

Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated …

Jul 11, 2026
CVE-2026-56240
4.3 MEDIUM

Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass …

Jul 11, 2026
CVE-2026-57828
8.8 HIGH

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Jul 11, 2026
CVE-2026-57827
9.8 CRITICAL

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jul 11, 2026
CVE-2026-1359
8.8 HIGH

The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Jul 11, 2026
CVE-2026-9282
7.5 HIGH

The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This …

Jul 11, 2026
CVE-2026-9017
5.3 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This …

Jul 11, 2026
CVE-2026-6939
7.2 HIGH

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'approval_code' parameter in all versions up to, and including, …

Jul 11, 2026
CVE-2026-6801
5.3 MEDIUM

The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the context_blog_modal_popup. This makes …

Jul 11, 2026
CVE-2026-4661
7.5 HIGH

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter …

Jul 11, 2026
CVE-2026-1382
6.4 MEDIUM

The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode in all versions up to, and including, 1.0.7 due …

Jul 11, 2026
CVE-2026-15155
8.8 HIGH

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authenticated Account Takeover via Email Header Injection in …

Jul 11, 2026
CVE-2026-15010
6.4 MEDIUM

The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.4.5 via the Topic Form Additional …

Jul 11, 2026
CVE-2026-12994
5.3 MEDIUM

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.7.27. This is …

Jul 11, 2026
CVE-2026-12738
4.3 MEDIUM

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 11, 2026
CVE-2026-12126
6.4 MEDIUM

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Attachment 'post_title' in all versions up to, …

Jul 11, 2026
CVE-2026-12103
4.3 MEDIUM

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the …

Jul 11, 2026
CVE-2026-11901
5.3 MEDIUM

The WP Hotel Booking plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 2.3.1. This is …

Jul 11, 2026
CVE-2026-11898
4.4 MEDIUM

The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due …

Jul 11, 2026
CVE-2026-11591
4.4 MEDIUM

The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 13.3 …

Jul 11, 2026
CVE-2026-10865
5.3 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). …

Jul 11, 2026
CVE-2026-10041
4.3 MEDIUM

The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.7.27 …

Jul 11, 2026
CVE-2025-6784
8.8 HIGH

The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0.3.5 via the 'code-engine' shortcode. This …

Jul 11, 2026
CVE-2025-5017
4.9 MEDIUM

The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the ‘uid’ parameter in all versions up to, …

Jul 11, 2026
CVE-2026-7655
8.1 HIGH

The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the …

Jul 11, 2026
CVE-2026-13378
7.2 HIGH

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all …

Jul 11, 2026
CVE-2026-9738
4.4 MEDIUM

The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and …

Jul 11, 2026
CVE-2026-7620
4.3 MEDIUM

The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the …

Jul 11, 2026
CVE-2026-7559
4.3 MEDIUM

The Affilia – Affiliate Program & Referral Tracking for WordPress plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, …

Jul 11, 2026
CVE-2026-6804
5.3 MEDIUM

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This …

Jul 11, 2026
CVE-2026-6803
5.3 MEDIUM

The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This …

Jul 11, 2026
CVE-2026-3576
7.2 HIGH

The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local File Inclusion in all versions up to, and …

Jul 11, 2026
CVE-2026-3552
4.3 MEDIUM

The SurfLink - Ultimate Link Manager plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the ajax_import_410() function …

Jul 11, 2026
CVE-2026-2354
8.8 HIGH

The Swiss Toolkit For WP plugin for WordPress is vulnerable to arbitrary file upload due to a flawed file type validation bypass in the `upload_extension_files()` …

Jul 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.