CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-4945
5.3 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Sep 7, 2026
CVE-2026-12853
5.4 MEDIUM

The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not …

Sep 7, 2026
CVE-2022-51018
6.5 MEDIUM

PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable …

Sep 7, 2026
CVE-2022-51017
7.5 HIGH

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 …

Sep 7, 2026
CVE-2022-51016
6.1 MEDIUM

PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key corresponding …

Sep 7, 2026
CVE-2022-51015
6.5 MEDIUM

PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within InventoryTransactionPacket). A remote authenticated attacker …

Sep 7, 2026
CVE-2022-51014
6.5 MEDIUM

PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form response …

Sep 7, 2026
CVE-2022-51013
6.5 MEDIUM

PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or …

Sep 7, 2026
CVE-2022-51012
6.5 MEDIUM

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions …

Sep 7, 2026
CVE-2022-51011
4.3 MEDIUM

PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large …

Sep 7, 2026
CVE-2022-51010
6.5 MEDIUM

PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the …

Sep 7, 2026
CVE-2026-86404
8.8 HIGH

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and …

Sep 7, 2026
CVE-2026-86301
3.5 LOW

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. …

Sep 7, 2026
CVE-2026-86300
7.3 HIGH

A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentication. The …

Sep 7, 2026
CVE-2026-86299
9.9 CRITICAL

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of …

Sep 7, 2026
CVE-2026-78325

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in …

Sep 7, 2026
CVE-2026-2390
6.4 MEDIUM

The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, …

Sep 7, 2026
CVE-2026-86351
6.1 MEDIUM

Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with /. That check is insufficient because protocol-relative URLs …

Sep 7, 2026
CVE-2026-86298
7.3 HIGH

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a …

Sep 7, 2026
CVE-2026-86297
8.1 HIGH

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. …

Sep 7, 2026
CVE-2026-86296
10.0 CRITICAL

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes …

Sep 7, 2026
CVE-2026-86295
8.3 HIGH

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the …

Sep 7, 2026
CVE-2026-86294
4.3 MEDIUM

A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of …

Sep 7, 2026
CVE-2026-85640
6.3 MEDIUM

Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component

Sep 7, 2026
CVE-2026-85201

In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through …

Sep 7, 2026
CVE-2026-82325

A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages

Sep 7, 2026
CVE-2026-77699
5.0 MEDIUM

Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.

Sep 7, 2026
CVE-2026-77697
6.3 MEDIUM

Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction

Sep 7, 2026
CVE-2026-19204

A client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memory …

Sep 7, 2026
CVE-2025-52657
3.5 LOW

HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact …

Sep 7, 2026
CVE-2025-52652
3.5 LOW

HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from …

Sep 7, 2026
CVE-2025-52651
3.5 LOW

HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.

Sep 7, 2026
CVE-2026-86347
6.5 MEDIUM

Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry for templates/uploadFile used the wildcard *. This bypasses the intended …

Sep 7, 2026
CVE-2026-86293
6.5 MEDIUM

A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of …

Sep 7, 2026
CVE-2026-86292
7.3 HIGH

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. …

Sep 7, 2026
CVE-2026-86291
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/us_edit1.php. Such manipulation of …

Sep 7, 2026
CVE-2026-84173

In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An …

Sep 7, 2026
CVE-2026-77698
5.7 MEDIUM

Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.

Sep 7, 2026
CVE-2026-86342
4.3 MEDIUM

Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview performed correlation lookups against attributes from events without applying …

Sep 7, 2026
CVE-2026-86332
6.5 MEDIUM

A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and …

Sep 7, 2026
CVE-2026-86290
7.3 HIGH

A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument …

Sep 7, 2026
CVE-2026-86289
4.3 MEDIUM

A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing …

Sep 7, 2026
CVE-2026-86288
6.3 MEDIUM

A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization …

Sep 7, 2026
CVE-2026-86285
4.3 MEDIUM

A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/AttachmentController.php of the component Attachment …

Sep 7, 2026
CVE-2026-84732

Retransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that …

Sep 7, 2026
CVE-2026-84186

Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the client’s IP address to be spoofed via the X-Forwarded-For header when …

Sep 7, 2026
CVE-2026-18796

Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally stored …

Sep 7, 2026
CVE-2026-14297

A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer to overflow …

Sep 7, 2026
CVE-2026-86284
5.3 MEDIUM

A security vulnerability has been detected in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected by this vulnerability is the function getOption of the file travel/src/main/java/com/controller/CommonController.java. The …

Sep 7, 2026
CVE-2026-86282
7.3 HIGH

A weakness has been identified in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Affected is an unknown function of the file travel/src/main/java/com/controller/CommonController.java of the component CommonDao. Executing …

Sep 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.