CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-58023
8.4 HIGH

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

Jul 23, 2026
CVE-2026-9713
7.5 HIGH

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON …

Jul 23, 2026
CVE-2026-12421
7.2 HIGH

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to …

Jul 23, 2026
CVE-2026-14291
7.5 HIGH

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker …

Jul 23, 2026
CVE-2026-12082
7.5 HIGH

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify …

Jul 23, 2026
CVE-2026-7534
7.2 HIGH

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and …

Jul 23, 2026
CVE-2026-7232
7.2 HIGH

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due …

Jul 23, 2026
CVE-2026-64600
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an …

Jul 23, 2026
CVE-2026-15074
7.5 HIGH

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of …

Jul 23, 2026
CVE-2026-16632
7.3 HIGH

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame …

Jul 23, 2026
CVE-2026-61246
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60455
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60439
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60373
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60371
8.0 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60370
7.5 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60368
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-38766
7.8 HIGH

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

Jul 22, 2026
CVE-2026-38765
7.8 HIGH

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

Jul 22, 2026
CVE-2026-64797
7.5 HIGH

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. …

Jul 22, 2026
CVE-2026-64792
7.5 HIGH

Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content …

Jul 22, 2026
CVE-2026-64791
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not …

Jul 22, 2026
CVE-2026-63685
8.8 HIGH

Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and …

Jul 22, 2026
CVE-2026-63684
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor …

Jul 22, 2026
CVE-2026-63683
7.5 HIGH

Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote …

Jul 22, 2026
CVE-2026-63280
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens …

Jul 22, 2026
CVE-2026-63265
8.0 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints …

Jul 22, 2026
CVE-2026-13089
7.5 HIGH

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin …

Jul 22, 2026
CVE-2025-60835
7.8 HIGH

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

Jul 22, 2026
CVE-2025-50330
8.8 HIGH

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

Jul 22, 2026
CVE-2025-50327
8.8 HIGH

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the …

Jul 22, 2026
CVE-2025-50324
8.8 HIGH

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

Jul 22, 2026
CVE-2025-44090
8.8 HIGH

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Jul 22, 2026
CVE-2025-44089
8.8 HIGH

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Jul 22, 2026
CVE-2026-64829
7.4 HIGH

Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password …

Jul 22, 2026
CVE-2026-14899
7.5 HIGH

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, …

Jul 22, 2026
CVE-2026-14881
7.8 HIGH

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it …

Jul 22, 2026
CVE-2026-13078
7.7 HIGH

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read …

Jul 22, 2026
CVE-2026-13077
7.1 HIGH

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The …

Jul 22, 2026
CVE-2026-13072
8.1 HIGH

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory …

Jul 22, 2026
CVE-2026-13059
8.1 HIGH

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to …

Jul 22, 2026
CVE-2026-64835
8.8 HIGH

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds …

Jul 22, 2026
CVE-2026-64834
7.5 HIGH

FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service …

Jul 22, 2026
CVE-2026-64833
7.1 HIGH

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying …

Jul 22, 2026
CVE-2026-64832
8.8 HIGH

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by …

Jul 22, 2026
CVE-2026-16157
7.8 HIGH

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on …

Jul 22, 2026
CVE-2026-65013
8.8 HIGH

Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources …

Jul 22, 2026
CVE-2026-64831
8.8 HIGH

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses …

Jul 22, 2026
CVE-2026-64830
8.8 HIGH

FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by …

Jul 22, 2026
CVE-2026-49499
8.8 HIGH

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote …

Jul 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.