CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-75861
6.5 MEDIUM

The Ultimate Gift Cards for WooCommerce WordPress plugin before 3.2.10 does not verify that the user redeeming a gift card is its intended recipient, allowing …

Sep 9, 2026
CVE-2026-19946
4.3 MEDIUM

The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability …

Sep 9, 2026
CVE-2026-18042
5.3 MEDIUM

The WP Travel WordPress plugin before 12.0.2 does not verify that the requester is authorized to act on the booking targeted by one of its …

Sep 9, 2026
CVE-2026-16960
7.5 HIGH

The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing …

Sep 9, 2026
CVE-2026-14962
8.6 HIGH

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, …

Sep 9, 2026
CVE-2026-13146
3.7 LOW

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by its bank-deposit slip submission, allowing an …

Sep 9, 2026
CVE-2026-13144
3.7 LOW

The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the targeted booking on one branch of …

Sep 9, 2026
CVE-2025-15690
6.8 MEDIUM

The Content Mask WordPress plugin before 1.8.5.6 does not properly sanitise and escape content submitted with a post before outputting it in the pages it …

Sep 9, 2026
CVE-2026-87737
5.9 MEDIUM

An issue was discovered in the mirage-crypto-ec package before 2.4.0 for OCaml. There is a timing side channel for NIST elliptic-curve scalar multiplication: the time …

Sep 9, 2026
CVE-2026-87736
4.3 MEDIUM

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.

Sep 9, 2026
CVE-2026-87735
4.3 MEDIUM

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or …

Sep 9, 2026
CVE-2026-87734
7.5 HIGH

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

Sep 9, 2026
CVE-2026-87733
6.2 MEDIUM

An issue was discovered in the mirage-crypto-ec function before 2.2.0 for OCaml. The ECDSA functions {P256,P384,P521}.Dsa.pub_of_octets accept 0x00, the encoding of the point at infinity, …

Sep 9, 2026
CVE-2026-87732
6.2 MEDIUM

An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer …

Sep 9, 2026
CVE-2026-21113

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

Sep 9, 2026
CVE-2026-21112

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required …

Sep 9, 2026
CVE-2026-21111

Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21110

Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.

Sep 9, 2026
CVE-2026-21109

Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.

Sep 9, 2026
CVE-2026-21108

Improper export of android application components in Bixby Touch prior to version 4.3.01.17 allows local attackers to access sensitive information.

Sep 9, 2026
CVE-2026-21107

Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21106

Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.

Sep 9, 2026
CVE-2026-21105

Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.

Sep 9, 2026
CVE-2026-21104
6.7 MEDIUM

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Sep 9, 2026
CVE-2026-21103
6.1 MEDIUM

Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

Sep 9, 2026
CVE-2026-21102
6.7 MEDIUM

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

Sep 9, 2026
CVE-2026-21101
6.7 MEDIUM

Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

Sep 9, 2026
CVE-2026-21100
7.1 HIGH

Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.

Sep 9, 2026
CVE-2026-21099
5.5 MEDIUM

Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

Sep 9, 2026
CVE-2026-21098

Improper access control in Link to Windows prior to SMR Sep-2026 Release 1 allows local attackers to establish a connection with the PC without proper …

Sep 9, 2026
CVE-2026-21097
6.7 MEDIUM

Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

Sep 9, 2026
CVE-2026-21096
9.8 CRITICAL

Heap-based buffer overflow in JPEG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Sep 9, 2026
CVE-2026-21095
9.8 CRITICAL

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Sep 9, 2026
CVE-2026-21094
8.8 HIGH

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21093
6.7 MEDIUM

Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21092
5.3 MEDIUM

Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

Sep 9, 2026
CVE-2026-21091
7.8 HIGH

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21090
7.8 HIGH

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21089
7.8 HIGH

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21088
7.8 HIGH

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21087
7.8 HIGH

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

Sep 9, 2026
CVE-2026-21086

Improper authorization in ProxyHandler prior to SMR Aug-2026 Release 1 allows local attackers to access proxy configuration.

Sep 9, 2026
CVE-2026-21085
6.7 MEDIUM

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-19945
6.4 MEDIUM

The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 2.2.1 due …

Sep 9, 2026
CVE-2026-11821
5.4 MEDIUM

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Sep 9, 2026
CVE-2026-84293
7.2 HIGH

The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, …

Sep 9, 2026
CVE-2026-81647
5.3 MEDIUM

Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

Sep 9, 2026
CVE-2026-81646
5.9 MEDIUM

Out-of-bounds read vulnerability in the graphics module. Impact: Successful exploitation of this vulnerability may affect availability.

Sep 9, 2026
CVE-2026-81644
4.3 MEDIUM

DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

Sep 9, 2026
CVE-2026-7804
6.1 MEDIUM

The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpf_fid' parameter in all versions up to, …

Sep 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.