CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-80931
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: w1: ds28e17: reject an oversize length on an I2C block read w1_f19_i2c_master_transfer() is the master_xfer …

Sep 11, 2026
CVE-2026-80930

In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout i2c_nuvoton_wait_for_stat() enables the IRQ before waiting for the …

Sep 11, 2026
CVE-2026-80929
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sysctl: move the "cad_pid" entry from pid_table[] to kern_reboot_table[] cad_pid is global, and kill_cad_pid() is …

Sep 11, 2026
CVE-2026-80928
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smack: fix cred UAF in smack_file_send_sigiotask() When inspecting the credentials of another task, objective credentials …

Sep 11, 2026
CVE-2026-80927

In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() If the auxiliary clock is disabled …

Sep 11, 2026
CVE-2026-80926
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences …

Sep 11, 2026
CVE-2026-79035
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context …

Sep 11, 2026
CVE-2026-78547

Out-of-bounds write vulnerability in Citrix Citrix Workspace app for Windows. This issue affects Citrix Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 …

Sep 11, 2026
CVE-2026-78546

Out-of-bounds read vulnerability in Citirx Workspace app for Windows. This issue affects Workspace app for Windows: before 2603.11 Current Release (CR), before 2507.1 LTSR CU3, …

Sep 11, 2026
CVE-2026-77490
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Sep 11, 2026
CVE-2026-68526

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event …

Sep 11, 2026
CVE-2026-54135
7.5 HIGH

AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP …

Sep 11, 2026
CVE-2026-53952
9.8 CRITICAL

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS …

Sep 11, 2026
CVE-2026-52630
9.8 CRITICAL

SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php

Sep 11, 2026
CVE-2026-49463
6.5 MEDIUM

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version …

Sep 11, 2026
CVE-2026-49462
5.3 MEDIUM

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and …

Sep 11, 2026
CVE-2026-89329
6.2 MEDIUM

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands …

Sep 11, 2026
CVE-2026-81910
6.5 MEDIUM

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color …

Sep 11, 2026
CVE-2026-79396
9.8 CRITICAL

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled …

Sep 11, 2026
CVE-2026-79395
9.8 CRITICAL

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows …

Sep 11, 2026
CVE-2026-79394
7.5 HIGH

An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships …

Sep 11, 2026
CVE-2026-79393
7.5 HIGH

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier …

Sep 11, 2026
CVE-2026-79362

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated …

Sep 11, 2026
CVE-2026-71646
7.5 HIGH

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() …

Sep 11, 2026
CVE-2026-62140
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.

Sep 11, 2026
CVE-2026-62139
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

Sep 11, 2026
CVE-2026-62138
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.

Sep 11, 2026
CVE-2026-62137
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.

Sep 11, 2026
CVE-2026-62136
5.3 MEDIUM

Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.

Sep 11, 2026
CVE-2026-62135
5.3 MEDIUM

Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.

Sep 11, 2026
CVE-2026-62134
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.

Sep 11, 2026
CVE-2026-62133
5.4 MEDIUM

Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.

Sep 11, 2026
CVE-2026-62132
5.3 MEDIUM

Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.

Sep 11, 2026
CVE-2026-62114
5.3 MEDIUM

Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.

Sep 11, 2026
CVE-2026-62113
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.

Sep 11, 2026
CVE-2026-62112
7.6 HIGH

Editor SQL Injection in Amelia <= 2.4.9 versions.

Sep 11, 2026
CVE-2026-62111
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.

Sep 11, 2026
CVE-2026-62110
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.

Sep 11, 2026
CVE-2026-62109
7.6 HIGH

Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.

Sep 11, 2026
CVE-2026-62107
8.8 HIGH

Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

Sep 11, 2026
CVE-2026-62106
8.8 HIGH

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

Sep 11, 2026
CVE-2026-62105
9.8 CRITICAL

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

Sep 11, 2026
CVE-2026-62103
9.8 CRITICAL

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

Sep 11, 2026
CVE-2026-62102
8.8 HIGH

Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

Sep 11, 2026
CVE-2026-62089
7.1 HIGH

Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.

Sep 11, 2026
CVE-2026-62088
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

Sep 11, 2026
CVE-2026-54072
9.3 CRITICAL

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When …

Sep 11, 2026
CVE-2026-27378
5.3 MEDIUM

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

Sep 11, 2026
CVE-2025-69904

Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. …

Sep 11, 2026
CVE-2026-9160
4.3 MEDIUM

Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website …

Sep 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.