CVE Database

45611+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11575
7.5 HIGH

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback …

Jul 17, 2026
CVE-2026-13765
7.5 HIGH

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Jul 17, 2026
CVE-2026-13352
8.8 HIGH

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File …

Jul 17, 2026
CVE-2026-15395
7.2 HIGH

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions …

Jul 17, 2026
CVE-2026-62387
7.1 HIGH

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. …

Jul 17, 2026
CVE-2026-62386
7.5 HIGH

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens …

Jul 17, 2026
CVE-2026-62234
8.1 HIGH

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create webhooks with file://, dict://, or gopher:// …

Jul 17, 2026
CVE-2026-62233
8.8 HIGH

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.users.write managers to escalate to super-admin. Attackers can mint …

Jul 17, 2026
CVE-2026-62232
7.4 HIGH

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user existence, not authorization, during the …

Jul 17, 2026
CVE-2026-62231
8.1 HIGH

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, but the ApiKeyAuthenticator class …

Jul 17, 2026
CVE-2026-62230
7.5 HIGH

Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml, .php, .json, etc.) lack the [NC] …

Jul 17, 2026
CVE-2026-62229
8.8 HIGH

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute actions beyond intended authorization. Attackers can …

Jul 17, 2026
CVE-2026-62228
8.8 HIGH

OpenClaw before 2026.6.5 contain an authorization bypass vulnerability in node exec approvals that allows lower-trust callers to execute actions beyond their intended authorization by using …

Jul 17, 2026
CVE-2026-62227
7.7 HIGH

OpenClaw 2026.4.14 before 2026.5.26 contain a server-side request forgery vulnerability in browser snapshot routes that fail to validate post-navigation destinations. Attackers with lower-trust access can …

Jul 17, 2026
CVE-2026-62226
8.5 HIGH

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to properly validate current-tab URL checks. Attackers with lower-trust …

Jul 17, 2026
CVE-2026-62223
8.8 HIGH

OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in the device-pair approval feature that allows lower-trust callers to execute actions beyond their intended authorization. Attackers …

Jul 17, 2026
CVE-2026-62222
7.8 HIGH

OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of untrusted workspace plugins. Attackers with lower-trust caller access or control over configured …

Jul 17, 2026
CVE-2026-62219
7.1 HIGH

OpenClaw 2026.2.12 before 2026.5.26 contain an authorization bypass vulnerability in the hooks allowedAgentIds validation. A lower-trust caller or configured input path can bypass agent ID …

Jul 17, 2026
CVE-2026-62218
8.8 HIGH

OpenClaw 2026.1.20 before 2026.5.27 contain an authorization bypass vulnerability in the device.pair.approve feature that allows lower-trust callers to bypass role-management checks. Attackers can perform actions …

Jul 17, 2026
CVE-2026-62217
8.8 HIGH

OpenClaw 2026.5.14-beta.1 before 2026.5.27 contain an authorization flaw in the QQBot exec approvals feature. When the feature is enabled and reachable, a lower-trust caller or …

Jul 17, 2026
CVE-2026-62215
8.0 HIGH

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability in HTTP Canvas responses that allows lower-trust callers to forge trusted A2UI actions. Attackers can perform …

Jul 17, 2026
CVE-2026-62212
7.1 HIGH

OpenClaw before 2026.5.28 contains a race condition in the MS Teams safeFetch DNS rebinding check. When the affected feature is enabled and reachable, a lower-trust …

Jul 17, 2026
CVE-2026-62209
8.1 HIGH

OpenClaw versions 2026.5.10-beta.1 before 2026.6.5 contain an authorization bypass in the ClickClack agent-mode dispatch feature, which could ignore the toolsAllow policy check. When the affected …

Jul 17, 2026
CVE-2026-62207
8.8 HIGH

OpenClaw versions before 2026.6.5 contain an authentication bypass vulnerability that allows lower-trust callers to reach admin-scoped tools. Attackers can perform actions requiring stronger authorization by …

Jul 17, 2026
CVE-2026-62206
7.1 HIGH

OpenClaw versions before 2026.6.9 contain a missing authorization vulnerability in Discord moderation actions. In affected versions, a lower-trust caller or configured input path could perform …

Jul 17, 2026
CVE-2026-62205
7.1 HIGH

OpenClaw versions 2026.4.12-beta.1 before 2026.6.6 contain a missing-authorization vulnerability in the MS Teams message actions feature. When the affected feature is enabled and reachable, a …

Jul 17, 2026
CVE-2026-62203
8.8 HIGH

OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize rustup startup variables. Attackers with lower-trust caller …

Jul 17, 2026
CVE-2026-62202
8.8 HIGH

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows lower-trust callers to regain denied execution tools. Attackers can …

Jul 17, 2026
CVE-2026-62201
7.7 HIGH

OpenClaw versions before 2026.6.6 contain a network policy bypass vulnerability in the sandbox exec-server that allows lower-trust callers to reach internal network destinations blocked by …

Jul 17, 2026
CVE-2026-54340
7.5 HIGH

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines …

Jul 17, 2026
CVE-2026-39359
7.5 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.14.4, a …

Jul 17, 2026
CVE-2026-34150
7.5 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 1.0.0 and above, prior to 4.14.5, a heap …

Jul 17, 2026
CVE-2026-44453
7.5 HIGH

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack …

Jul 16, 2026
CVE-2026-44436
7.5 HIGH

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, Quicly is vulnerable to a …

Jul 16, 2026
CVE-2026-44435
7.5 HIGH

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised …

Jul 16, 2026
CVE-2026-43978
8.1 HIGH

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account …

Jul 16, 2026
CVE-2026-43977
7.5 HIGH

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, …

Jul 16, 2026
CVE-2026-59117
7.5 HIGH

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

Jul 16, 2026
CVE-2026-58598
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.

Jul 16, 2026
CVE-2026-57077
7.7 HIGH

YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In the bundled libsyck newline_len and is_newline dereference …

Jul 16, 2026
CVE-2026-57076
7.8 HIGH

YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor. In the bundled libsyck …

Jul 16, 2026
CVE-2026-53411
7.8 HIGH

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user …

Jul 16, 2026
CVE-2026-55173
8.1 HIGH

WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete …

Jul 16, 2026
CVE-2026-53410
7.0 HIGH

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user …

Jul 16, 2026
CVE-2026-53409
7.8 HIGH

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.

Jul 16, 2026
CVE-2026-44023
8.6 HIGH

Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not …

Jul 16, 2026
CVE-2026-44019
8.1 HIGH

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow …

Jul 16, 2026
CVE-2026-33692
7.5 HIGH

WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The …

Jul 16, 2026
CVE-2024-34268
7.1 HIGH

EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers …

Jul 16, 2026
CVE-2024-32386
7.3 HIGH

Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism.

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.