CVE Database

114567+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-56032
9.8 CRITICAL

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

Jun 26, 2026
CVE-2026-56031
8.1 HIGH

Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.

Jun 26, 2026
CVE-2026-56030
9.8 CRITICAL

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

Jun 26, 2026
CVE-2026-56029
7.5 HIGH

Unauthenticated Broken Authentication in CorvusPay WooCommerce Payment Gateway <= 2.7.4 versions.

Jun 26, 2026
CVE-2026-56028
9.8 CRITICAL

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.

Jun 26, 2026
CVE-2026-56027
9.9 CRITICAL

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

Jun 26, 2026
CVE-2026-56026
6.4 MEDIUM

Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

Jun 26, 2026
CVE-2026-56025
7.5 HIGH

Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.

Jun 26, 2026
CVE-2026-56011
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.

Jun 26, 2026
CVE-2026-56010
8.8 HIGH

Subscriber Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

Jun 26, 2026
CVE-2026-56008
8.8 HIGH

Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions.

Jun 26, 2026
CVE-2026-54847
7.5 HIGH

Unauthenticated Broken Access Control in Stylish Cost Calculator <= 8.3.9 versions.

Jun 26, 2026
CVE-2026-54846
7.5 HIGH

Unauthenticated Broken Access Control in Syncee Premium Dropshipping &amp; Wholesale <= 1.0.27 versions.

Jun 26, 2026
CVE-2026-54840
7.3 HIGH

Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.

Jun 26, 2026
CVE-2026-54839
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups <= 2.0.9 versions.

Jun 26, 2026
CVE-2026-54837
7.5 HIGH

Unauthenticated Broken Access Control in Intranet &amp; Private Site &#8211; All-In-One Intranet <= 1.8.1 versions.

Jun 26, 2026
CVE-2026-54835
7.5 HIGH

Unauthenticated Broken Access Control in Five Star Restaurant Menu <= 2.5.2 versions.

Jun 26, 2026
CVE-2026-54834
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

Jun 26, 2026
CVE-2026-54833
7.4 HIGH

Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.

Jun 26, 2026
CVE-2026-54832
7.5 HIGH

Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.

Jun 26, 2026
CVE-2026-54831
9.3 CRITICAL

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

Jun 26, 2026
CVE-2026-54827
9.3 CRITICAL

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

Jun 26, 2026
CVE-2026-54826
7.6 HIGH

Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

Jun 26, 2026
CVE-2026-54825
9.3 CRITICAL

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

Jun 26, 2026
CVE-2026-54824
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

Jun 26, 2026
CVE-2026-54820
9.3 CRITICAL

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

Jun 26, 2026
CVE-2026-52701
6.5 MEDIUM

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

Jun 26, 2026
CVE-2026-4339
6.5 MEDIUM

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost …

Jun 26, 2026
CVE-2026-45257
7.8 HIGH

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does …

Jun 26, 2026
CVE-2026-45256
5.5 MEDIUM

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not check the …

Jun 26, 2026
CVE-2026-3472
3.5 LOW

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, …

Jun 26, 2026
CVE-2026-30041
7.5 HIGH

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service …

Jun 26, 2026
CVE-2026-30040
6.5 MEDIUM

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the …

Jun 26, 2026
CVE-2026-24547
5.3 MEDIUM

Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.

Jun 26, 2026
CVE-2025-68075
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

Jun 26, 2026
CVE-2025-68074
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

Jun 26, 2026
CVE-2025-68064
7.5 HIGH

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

Jun 26, 2026
CVE-2025-68063
7.5 HIGH

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

Jun 26, 2026
CVE-2025-68052
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

Jun 26, 2026
CVE-2025-66123
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

Jun 26, 2026
CVE-2025-64637
5.3 MEDIUM

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

Jun 26, 2026
CVE-2025-64636
5.3 MEDIUM

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

Jun 26, 2026
CVE-2025-63079
4.3 MEDIUM

Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

Jun 26, 2026
CVE-2025-63078
4.3 MEDIUM

Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.

Jun 26, 2026
CVE-2025-63041
5.4 MEDIUM

Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

Jun 26, 2026
CVE-2026-57940

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to …

Jun 26, 2026
CVE-2026-57926
2.6 LOW

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Jun 26, 2026
CVE-2026-57925
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

Jun 26, 2026
CVE-2026-57924
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Jun 26, 2026
CVE-2026-57923
5.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

Jun 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.