CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-86257
5.4 MEDIUM

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. …

Sep 6, 2026
CVE-2026-86256
5.4 MEDIUM

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view …

Sep 6, 2026
CVE-2026-86255
6.5 MEDIUM

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can …

Sep 6, 2026
CVE-2026-86254
6.8 MEDIUM

wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of …

Sep 6, 2026
CVE-2026-86253
5.9 MEDIUM

h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dot segments (%2e%2e) …

Sep 6, 2026
CVE-2026-86252
5.3 MEDIUM

h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including …

Sep 6, 2026
CVE-2026-86251
5.9 MEDIUM

h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (e.g. …

Sep 6, 2026
CVE-2026-86250
7.5 HIGH

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted …

Sep 6, 2026
CVE-2026-86242
8.1 HIGH

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled …

Sep 6, 2026
CVE-2026-86212
4.3 MEDIUM

A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attack …

Sep 6, 2026
CVE-2026-86205
5.4 MEDIUM

h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. Attackers …

Sep 6, 2026
CVE-2022-51009
7.5 HIGH

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with …

Sep 6, 2026
CVE-2022-51008
5.3 MEDIUM

PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server …

Sep 6, 2026
CVE-2021-48007
6.5 MEDIUM

PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with …

Sep 6, 2026
CVE-2021-48006
3.3 LOW

PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removes an …

Sep 6, 2026
CVE-2020-37277
6.5 MEDIUM

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple …

Sep 6, 2026
CVE-2026-86211
7.3 HIGH

A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation …

Sep 6, 2026
CVE-2026-86210
7.3 HIGH

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Sep 6, 2026
CVE-2026-86209
7.3 HIGH

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of …

Sep 6, 2026
CVE-2026-86208
7.3 HIGH

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation …

Sep 6, 2026
CVE-2026-80439
4.8 MEDIUM

The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it …

Sep 6, 2026
CVE-2026-80437
4.8 MEDIUM

The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content …

Sep 6, 2026
CVE-2026-19862
4.8 MEDIUM

The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them …

Sep 6, 2026
CVE-2026-19859
6.5 MEDIUM

The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes …

Sep 6, 2026
CVE-2026-86183
5.3 MEDIUM

A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.php of the component dmWidget. Such manipulation …

Sep 6, 2026
CVE-2026-86182
4.3 MEDIUM

A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation …

Sep 6, 2026
CVE-2026-86181
3.5 LOW

A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component …

Sep 6, 2026
CVE-2026-86180
7.3 HIGH

A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php …

Sep 6, 2026
CVE-2026-86179
5.3 MEDIUM

A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup …

Sep 6, 2026
CVE-2026-86172
6.3 MEDIUM

A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID results …

Sep 6, 2026
CVE-2026-86171
6.3 MEDIUM

A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID …

Sep 6, 2026
CVE-2026-85038
5.3 MEDIUM

The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that …

Sep 6, 2026
CVE-2026-84219
7.5 HIGH

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store …

Sep 6, 2026
CVE-2026-84028
6.8 MEDIUM

The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users …

Sep 6, 2026
CVE-2026-75793
6.5 MEDIUM

The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an account …

Sep 6, 2026
CVE-2026-18480
8.8 HIGH

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, …

Sep 6, 2026
CVE-2026-13159
4.3 MEDIUM

The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, …

Sep 6, 2026
CVE-2026-86170
6.3 MEDIUM

A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument …

Sep 6, 2026
CVE-2026-86168
7.3 HIGH

A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation …

Sep 6, 2026
CVE-2026-86167
9.9 CRITICAL

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the …

Sep 6, 2026
CVE-2026-86166
8.8 HIGH

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing …

Sep 6, 2026
CVE-2026-86165
9.8 CRITICAL

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN …

Sep 6, 2026
CVE-2026-86164
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of …

Sep 6, 2026
CVE-2026-86163
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument …

Sep 6, 2026
CVE-2026-86218
9.8 CRITICAL KEV

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Sep 6, 2026
CVE-2026-86162
7.3 HIGH

A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument …

Sep 6, 2026
CVE-2026-86161
7.3 HIGH

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86160
7.3 HIGH

A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of …

Sep 6, 2026
CVE-2026-86159
7.3 HIGH

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument …

Sep 6, 2026
CVE-2026-75816
9.8 CRITICAL

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This …

Sep 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.