CVE Database

130945+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-3855
3.1 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-1168
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-19857
4.8 MEDIUM

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token …

Sep 16, 2026
CVE-2026-19619
4.7 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-19248

QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

Sep 16, 2026
CVE-2026-16794
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-13407
5.4 MEDIUM

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the …

Sep 16, 2026
CVE-2025-14871
7.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2024-11222
6.4 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 16, 2026
CVE-2026-92358
6.4 MEDIUM

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary …

Sep 16, 2026
CVE-2026-89328

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. …

Sep 16, 2026
CVE-2026-89327

The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing …

Sep 16, 2026
CVE-2026-88910

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media …

Sep 16, 2026
CVE-2026-87959

The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users …

Sep 16, 2026
CVE-2026-87907

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing …

Sep 16, 2026
CVE-2026-87896

The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated …

Sep 16, 2026
CVE-2026-87860

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make …

Sep 16, 2026
CVE-2026-87854

The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to …

Sep 16, 2026
CVE-2026-87828

The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as …

Sep 16, 2026
CVE-2026-86823

The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect …

Sep 16, 2026
CVE-2026-86784

The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, …

Sep 16, 2026
CVE-2026-86449

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities before applying a user supplied post status filter in one of its REST …

Sep 16, 2026
CVE-2026-86448

The LearnPress WordPress plugin before 4.4.7 does not perform any authentication, capability or nonce check before serving a previously generated order export file, allowing unauthenticated …

Sep 16, 2026
CVE-2026-86447

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative course tools, allowing unauthenticated attackers to list every …

Sep 16, 2026
CVE-2026-86445

The LearnPress WordPress plugin before 4.4.7 does not check the user's capabilities in one of its administrative template handlers, allowing unauthenticated attackers to retrieve the …

Sep 16, 2026
CVE-2026-86444

The LearnPress WordPress plugin before 4.4.7 does not escape a user supplied value before using it in an HTML attribute on a public page, allowing …

Sep 16, 2026
CVE-2026-85641

The Formidable Forms WordPress plugin before 6.35 does not restrict who can set the identifier recording which user last edited a form entry, and relies …

Sep 16, 2026
CVE-2026-85572

The Tutor LMS WordPress plugin before 4.0.8 does not check that a user has access to a course before returning its lesson discussion content, allowing …

Sep 16, 2026
CVE-2026-85569

The Tutor LMS WordPress plugin before 4.0.8 does not correctly determine whether an incoming request is addressed to its own REST API, and does not …

Sep 16, 2026
CVE-2026-85530

The GiveWP WordPress plugin before 4.16.8.1 does not consistently normalise a donor's e-mail address between the value it stores and the value it later uses …

Sep 16, 2026
CVE-2026-85349

The FluentBoards WordPress plugin before 2.0.15 does not properly verify authorization when returning the list of boards a user belongs to, allowing any authenticated user, …

Sep 16, 2026
CVE-2026-85131

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not perform CSRF or capability checks when processing bulk actions on its administration screens, and does …

Sep 16, 2026
CVE-2026-84907

The Eventin WordPress plugin before 4.1.24 does not properly authorise order finalisation when its offline (local) payment method is enabled, relying on a nonce that …

Sep 16, 2026
CVE-2026-84905

The Eventin WordPress plugin before 4.1.24 does not verify a user's capability to create accounts when adding a speaker, allowing users with contributor-level access and …

Sep 16, 2026
CVE-2026-84829

The Optimole WordPress plugin before 4.2.12 does not properly escape a user supplied value before using it to build an image tag attribute, allowing unauthenticated …

Sep 16, 2026
CVE-2026-84088

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.9 does not validate or sanitize a widget link setting before storing and using …

Sep 16, 2026
CVE-2026-82126

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check that a user is allowed to edit the specific …

Sep 16, 2026
CVE-2026-82125

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a …

Sep 16, 2026
CVE-2026-82124

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its …

Sep 16, 2026
CVE-2026-78474

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated …

Sep 16, 2026
CVE-2026-78472

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated …

Sep 16, 2026
CVE-2026-77702

The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets …

Sep 16, 2026
CVE-2026-76559

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the …

Sep 16, 2026
CVE-2026-76558

The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM …

Sep 16, 2026
CVE-2026-76557

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, …

Sep 16, 2026
CVE-2026-76556

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, …

Sep 16, 2026
CVE-2026-76555

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly …

Sep 16, 2026
CVE-2026-76553

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it …

Sep 16, 2026
CVE-2026-76552

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate the type, extension or content of files it retrieves from a user-supplied URL …

Sep 16, 2026
CVE-2026-76551

The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.