CVE Database

52246+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6672
6.4 MEDIUM

The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all versions up to, and …

May 6, 2026
CVE-2026-6344
4.9 MEDIUM

The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This is due to insufficient path …

May 6, 2026
CVE-2026-35254
6.1 MEDIUM

Vulnerability in the Oracle OCI CLI product of Oracle Open Source Projects. The supported versions that is affected is 3.77. Easily exploitable vulnerability allows unauthenticated …

May 6, 2026
CVE-2026-35253
4.7 MEDIUM

Vulnerability in the Oracle Macoron Tool product of Oracle Open Source Projects. The supported versions that is affected is v0.22.0. Easily exploitable vulnerability allows unauthenticated …

May 6, 2026
CVE-2026-2306
4.3 MEDIUM

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the …

May 6, 2026
CVE-2026-5753
6.5 MEDIUM

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to …

May 6, 2026
CVE-2026-3208
5.3 MEDIUM

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' …

May 6, 2026
CVE-2026-7573
5.0 MEDIUM

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete …

May 6, 2026
CVE-2026-7572
4.4 MEDIUM

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to …

May 6, 2026
CVE-2026-40934
6.8 MEDIUM

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a …

May 5, 2026
CVE-2026-41950
6.5 MEDIUM

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within …

May 5, 2026
CVE-2026-39402
6.5 MEDIUM

lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an …

May 5, 2026
CVE-2026-35527
5.0 MEDIUM

Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to …

May 5, 2026
CVE-2026-38947
6.1 MEDIUM

FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.

May 5, 2026
CVE-2026-35453
5.4 MEDIUM

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and …

May 5, 2026
CVE-2026-34527
5.3 MEDIUM

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high …

May 5, 2026
CVE-2026-33420
5.3 MEDIUM

Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that …

May 5, 2026
CVE-2026-32603
6.5 MEDIUM

Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie …

May 5, 2026
CVE-2026-31835
5.4 MEDIUM

Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and …

May 5, 2026
CVE-2026-43002
5.3 MEDIUM

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and …

May 5, 2026
CVE-2026-38432
6.1 MEDIUM

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email …

May 5, 2026
CVE-2026-7844
6.3 MEDIUM

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Compatible File …

May 5, 2026
CVE-2026-6907
4.3 MEDIUM

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). This …

May 5, 2026
CVE-2026-5766
5.3 MEDIUM

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` …

May 5, 2026
CVE-2026-39103
5.5 MEDIUM

Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svg_attributes.c, svg_parse_strings(), gf_svg_parse_attribute()

May 5, 2026
CVE-2026-35192
6.5 MEDIUM

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, …

May 5, 2026
CVE-2026-34956
5.9 MEDIUM

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote …

May 5, 2026
CVE-2026-34002
6.1 MEDIUM

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker …

May 5, 2026
CVE-2026-34000
6.1 MEDIUM

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, …

May 5, 2026
CVE-2025-61669
6.1 MEDIUM

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated …

May 5, 2026
CVE-2025-52206
4.7 MEDIUM

ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

May 5, 2026
CVE-2026-7778
5.0 MEDIUM

An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance …

May 5, 2026
CVE-2026-30246
6.5 MEDIUM

Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the cache middleware uses only the request path …

May 5, 2026
CVE-2026-28510
5.9 MEDIUM

eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably preserve the multi-factor authentication state across …

May 5, 2026
CVE-2026-27694
5.4 MEDIUM

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the email notification templates insert user-controlled device, geofence, and …

May 5, 2026
CVE-2026-27693
5.4 MEDIUM

Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML and GPX export functionality writes device names …

May 5, 2026
CVE-2026-27644
6.5 MEDIUM

Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and …

May 5, 2026
CVE-2026-6262
6.5 MEDIUM

The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is due to the upload_icons() function …

May 5, 2026
CVE-2026-43574
6.5 MEDIUM

OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolved approver lists are interpreted as explicit approval authorization. Attackers can resolve …

May 5, 2026
CVE-2026-43572
5.3 MEDIUM

OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO invoke handler that fails to apply sender allowlist checks. Attackers …

May 5, 2026
CVE-2026-43570
6.5 MEDIUM

OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository path handling that allows attackers to escape the expected repository root. …

May 5, 2026
CVE-2026-43568
6.5 MEDIUM

OpenClaw versions 2026.4.5 before 2026.4.10 contain a privilege escalation vulnerability allowing write-scoped operators to modify persistent memory dreaming settings. Attackers with write-scoped gateway access can …

May 5, 2026
CVE-2026-43567
6.5 MEDIUM

OpenClaw before 2026.4.10 contains a path traversal vulnerability in the screen_record tool's outPath parameter that bypasses workspace-only filesystem guards. Attackers can exploit this by specifying …

May 5, 2026
CVE-2026-43535
6.8 MEDIUM

OpenClaw before 2026.4.14 contains an authorization context reuse vulnerability in collect-mode queue batches that allows messages from different senders to inherit the final sender's authorization …

May 5, 2026
CVE-2026-43528
6.5 MEDIUM

OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with …

May 5, 2026
CVE-2026-42433
6.5 MEDIUM

OpenClaw before 2026.4.10 contains an authorization bypass vulnerability allowing operator.write message-tool paths to access Matrix profile persistence requiring admin-level authority. Attackers can exploit insufficient access …

May 5, 2026
CVE-2023-54349
6.1 MEDIUM

AmazCart CMS 3.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search functionality. Attackers …

May 5, 2026
CVE-2025-42611
6.5 MEDIUM

RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, …

May 5, 2026
CVE-2026-43868
5.3 MEDIUM

Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, …

May 5, 2026
CVE-2026-3601
4.3 MEDIUM

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function …

May 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.