CVE Database

57718+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-66038
6.5 MEDIUM

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory …

Jul 24, 2026
CVE-2026-66037
6.5 MEDIUM

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte …

Jul 24, 2026
CVE-2026-57531
5.4 MEDIUM

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's …

Jul 24, 2026
CVE-2026-57530
5.4 MEDIUM

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that allows attackers with document write access to execute arbitrary …

Jul 24, 2026
CVE-2026-65707
6.5 MEDIUM

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by submitting unsanitized POST parameters to the …

Jul 24, 2026
CVE-2026-8308
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services Website Template allows Reflected XSS. This issue …

Jul 24, 2026
CVE-2026-7007
4.6 MEDIUM

The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.c) before completing a mount. The validator checked the magic number, block size, revision …

Jul 24, 2026
CVE-2026-66007
6.5 MEDIUM

Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated …

Jul 24, 2026
CVE-2026-66006
5.3 MEDIUM

lakeFS through 1.83.0, fixed in commit 71a45ee, contains an authentication bypass vulnerability in the /setup_comm_prefs endpoint that allows unauthenticated attackers to overwrite operator metadata including …

Jul 24, 2026
CVE-2026-66005
6.3 MEDIUM

Jan through 0.8.4, fixed in commit 3e1c1e7, contains a CORS misconfiguration vulnerability in its local API server that allows network-adjacent attackers to bypass trusted host …

Jul 24, 2026
CVE-2026-66004
5.3 MEDIUM

BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitrary files by injecting traversal sequences in …

Jul 24, 2026
CVE-2026-49326
6.5 MEDIUM

Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. …

Jul 24, 2026
CVE-2026-17059
6.5 MEDIUM

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access management solution. …

Jul 24, 2026
CVE-2026-16802
6.5 MEDIUM

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to …

Jul 24, 2026
CVE-2026-16799
5.0 MEDIUM

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader …

Jul 24, 2026
CVE-2026-16798
6.5 MEDIUM

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped …

Jul 24, 2026
CVE-2026-17048
5.5 MEDIUM

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system …

Jul 24, 2026
CVE-2026-7484
5.3 MEDIUM

External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: …

Jul 24, 2026
CVE-2026-66010
6.1 MEDIUM

DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDLING.tagNameCheck, allowing attributes to bypass application security policies. Attackers can preserve sensitive …

Jul 24, 2026
CVE-2026-46452
5.3 MEDIUM

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken data toward application resulting in memory pressure and …

Jul 24, 2026
CVE-2026-45812
6.5 MEDIUM

Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple …

Jul 24, 2026
CVE-2026-16743
5.5 MEDIUM

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed …

Jul 24, 2026
CVE-2026-16730
5.5 MEDIUM

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, …

Jul 24, 2026
CVE-2026-15663
4.9 MEDIUM

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' …

Jul 24, 2026
CVE-2026-63317
5.6 MEDIUM

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code …

Jul 24, 2026
CVE-2026-15821
6.4 MEDIUM

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …

Jul 24, 2026
CVE-2026-15739
6.4 MEDIUM

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and …

Jul 24, 2026
CVE-2026-15346
6.1 MEDIUM

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, …

Jul 24, 2026
CVE-2026-16910
5.5 MEDIUM

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing …

Jul 24, 2026
CVE-2026-15755
6.4 MEDIUM

The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …

Jul 24, 2026
CVE-2026-15665
6.4 MEDIUM

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all …

Jul 24, 2026
CVE-2026-15653
6.4 MEDIUM

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in …

Jul 24, 2026
CVE-2026-15648
6.4 MEDIUM

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 …

Jul 24, 2026
CVE-2026-15464
6.4 MEDIUM

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 …

Jul 24, 2026
CVE-2026-15334
6.4 MEDIUM

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored …

Jul 24, 2026
CVE-2026-15333
6.4 MEDIUM

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored …

Jul 24, 2026
CVE-2026-12654
5.3 MEDIUM

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due …

Jul 24, 2026
CVE-2026-12689
5.4 MEDIUM

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with …

Jul 24, 2026
CVE-2026-12688
6.5 MEDIUM

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification …

Jul 24, 2026
CVE-2026-66139
4.8 MEDIUM

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

Jul 24, 2026
CVE-2026-54422
5.5 MEDIUM

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download …

Jul 24, 2026
CVE-2026-6454
6.4 MEDIUM

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient …

Jul 24, 2026
CVE-2026-15420
4.3 MEDIUM

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, …

Jul 24, 2026
CVE-2026-15100
6.4 MEDIUM

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, …

Jul 24, 2026
CVE-2026-13464
5.3 MEDIUM

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Jul 24, 2026
CVE-2026-11922
6.5 MEDIUM

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the …

Jul 24, 2026
CVE-2026-11354
5.3 MEDIUM

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This …

Jul 24, 2026
CVE-2025-9205
6.4 MEDIUM

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input …

Jul 24, 2026
CVE-2026-49159
6.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Jul 24, 2026
CVE-2026-50044
6.8 MEDIUM

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin credentials via weak hash or …

Jul 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.