CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-5757
7.5 HIGH

Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory, potentially leading to sensitive …

Jun 26, 2026
CVE-2026-47214
7.1 HIGH

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI …

Jun 26, 2026
CVE-2026-45195
7.8 HIGH

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside …

Jun 26, 2026
CVE-2026-44018
5.5 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing …

Jun 26, 2026
CVE-2026-21734
7.7 HIGH

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in …

Jun 26, 2026
CVE-2026-12411
8.4 HIGH

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via …

Jun 26, 2026
CVE-2026-0828
7.5 HIGH

Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.

Jun 26, 2026
CVE-2026-0685
9.8 CRITICAL

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution …

Jun 26, 2026
CVE-2025-11919
9.6 CRITICAL

The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file …

Jun 26, 2026
CVE-2023-20572

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the …

Jun 26, 2026
CVE-2023-20540

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary …

Jun 26, 2026
CVE-2026-9699
6.8 MEDIUM

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to …

Jun 26, 2026
CVE-2026-57667
8.5 HIGH

Sales Representative SQL Injection in Groundhogg <= 4.5 versions.

Jun 26, 2026
CVE-2026-57665
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.

Jun 26, 2026
CVE-2026-57664
4.3 MEDIUM

Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.

Jun 26, 2026
CVE-2026-57663
8.5 HIGH

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

Jun 26, 2026
CVE-2026-57662
8.5 HIGH

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

Jun 26, 2026
CVE-2026-57661
5.4 MEDIUM

Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.

Jun 26, 2026
CVE-2026-57660
5.3 MEDIUM

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.

Jun 26, 2026
CVE-2026-57659
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.

Jun 26, 2026
CVE-2026-57658
9.1 CRITICAL

Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.

Jun 26, 2026
CVE-2026-57657
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.

Jun 26, 2026
CVE-2026-57656
5.9 MEDIUM

Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.

Jun 26, 2026
CVE-2026-57655
8.2 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.

Jun 26, 2026
CVE-2026-57654
6.5 MEDIUM

Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

Jun 26, 2026
CVE-2026-57653
8.5 HIGH

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

Jun 26, 2026
CVE-2026-57652
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.

Jun 26, 2026
CVE-2026-57651
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

Jun 26, 2026
CVE-2026-57650
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.

Jun 26, 2026
CVE-2026-57649
4.3 MEDIUM

Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.

Jun 26, 2026
CVE-2026-57648
4.3 MEDIUM

Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.

Jun 26, 2026
CVE-2026-57647
7.5 HIGH

Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.

Jun 26, 2026
CVE-2026-57646
5.4 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.

Jun 26, 2026
CVE-2026-57645
8.1 HIGH

newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.

Jun 26, 2026
CVE-2026-57644
8.5 HIGH

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

Jun 26, 2026
CVE-2026-57643
8.5 HIGH

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

Jun 26, 2026
CVE-2026-57642
8.5 HIGH

Contributor SQL Injection in Gallery <= 4.7.8 versions.

Jun 26, 2026
CVE-2026-57641
6.5 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

Jun 26, 2026
CVE-2026-57640
4.3 MEDIUM

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.

Jun 26, 2026
CVE-2026-57638
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

Jun 26, 2026
CVE-2026-57637
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

Jun 26, 2026
CVE-2026-57636
8.5 HIGH

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

Jun 26, 2026
CVE-2026-57635
6.5 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.

Jun 26, 2026
CVE-2026-57634
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

Jun 26, 2026
CVE-2026-57633
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions.

Jun 26, 2026
CVE-2026-57632
5.4 MEDIUM

Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

Jun 26, 2026
CVE-2026-57631
7.6 HIGH

Administrator SQL Injection in Popup box <= 6.0.1 versions.

Jun 26, 2026
CVE-2026-57630
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.

Jun 26, 2026
CVE-2026-57629
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

Jun 26, 2026
CVE-2026-57628
7.6 HIGH

Administrator SQL Injection in WP All Import <= 4.0.1 versions.

Jun 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.