CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-85581
7.5 HIGH

SiYuan before v3.8.2 contains a denial of service vulnerability in the unauthenticated /api/system/uiproc endpoint that accepts and retains attacker-controlled process identifiers without size limits or …

Sep 4, 2026
CVE-2026-85580
6.5 MEDIUM

SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read …

Sep 4, 2026
CVE-2026-85579
4.3 MEDIUM

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs …

Sep 4, 2026
CVE-2026-85578
6.5 MEDIUM

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers …

Sep 4, 2026
CVE-2026-85577
5.4 MEDIUM

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag …

Sep 4, 2026
CVE-2026-19080
7.5 HIGH

Observable response discrepancy vulnerability in Menulux Software Inc. Menulux Portal allows Account Footprinting. This issue affects Menulux Portal: before 20260903211448.

Sep 4, 2026
CVE-2026-19051
7.1 HIGH

Plaintext storage of a password vulnerability in Menulux Software Inc. Menulux Portal allows Retrieve Embedded Sensitive Data. This issue affects Menulux Portal: before 20260903211448.

Sep 4, 2026
CVE-2026-19043
4.3 MEDIUM

Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448.

Sep 4, 2026
CVE-2026-18957
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: …

Sep 4, 2026
CVE-2026-85534
5.9 MEDIUM

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data …

Sep 4, 2026
CVE-2026-85512
7.3 HIGH

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation …

Sep 4, 2026
CVE-2026-84428
7.5 HIGH

fastify versions before 5.12.2 implement the case-insensitive nature of HTTP header names by lowercasing names in a route's header schema before compiling it, but the …

Sep 4, 2026
CVE-2026-84045
5.3 MEDIUM

The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before …

Sep 4, 2026
CVE-2026-79707

A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote …

Sep 4, 2026
CVE-2026-4644

A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to …

Sep 4, 2026
CVE-2026-27347
5.3 MEDIUM

Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.

Sep 4, 2026
CVE-2026-85547

A cross-site request forgery (CSRF) vulnerability exists in MISP due to form-security and CSRF protections being disabled based on whether an incoming request was identified …

Sep 4, 2026
CVE-2026-85546

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickEdit() helper, …

Sep 4, 2026
CVE-2026-85541
5.4 MEDIUM

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

Sep 4, 2026
CVE-2026-85540
8.8 HIGH

DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

Sep 4, 2026
CVE-2026-85184
9.1 CRITICAL

@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves …

Sep 4, 2026
CVE-2026-84504
8.1 HIGH

fastify versions before 5.12.2 treat the object resolved by a successful Ajv async validator as the value result protocol used by custom validator compilers. If …

Sep 4, 2026
CVE-2026-84469
7.5 HIGH

fastify versions before 5.12.2 decide whether to compile a request schema based on JavaScript truthiness, but JSON Schema Draft 7 defines the boolean false as …

Sep 4, 2026
CVE-2026-84044
5.3 MEDIUM

The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers …

Sep 4, 2026
CVE-2026-84043
5.3 MEDIUM

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark …

Sep 4, 2026
CVE-2026-82923
9.8 CRITICAL

The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers …

Sep 4, 2026
CVE-2026-81666
6.5 MEDIUM

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems …

Sep 4, 2026
CVE-2026-76169
7.5 HIGH

fastify versions >= 4.0.0 and before 5.12.2 can route a malformed URL sent under one plugin prefix to the custom not-found handler of a different …

Sep 4, 2026
CVE-2026-27086
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8.

Sep 4, 2026
CVE-2026-13148

Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10.

Sep 4, 2026
CVE-2026-85538

An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected attribute …

Sep 4, 2026
CVE-2026-85533

An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing …

Sep 4, 2026
CVE-2026-85528
5.3 MEDIUM

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to …

Sep 4, 2026
CVE-2026-85525
7.4 HIGH

Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP …

Sep 4, 2026
CVE-2026-85311
5.3 MEDIUM

Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60.

Sep 4, 2026
CVE-2026-81665
7.5 HIGH

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments …

Sep 4, 2026
CVE-2026-81302
7.8 HIGH

PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected …

Sep 4, 2026
CVE-2026-57777
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from …

Sep 4, 2026
CVE-2026-32480
5.3 MEDIUM

Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11.

Sep 4, 2026
CVE-2026-27432
5.4 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: …

Sep 4, 2026
CVE-2026-15937

Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to …

Sep 4, 2026
CVE-2026-85229
6.1 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache …

Sep 4, 2026
CVE-2026-85197
7.6 HIGH

A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client …

Sep 4, 2026
CVE-2026-80190
6.1 MEDIUM

Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability is likely mitigated via default CSP headers. …

Sep 4, 2026
CVE-2026-6217
6.3 MEDIUM

Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online …

Sep 4, 2026
CVE-2026-85094
8.8 HIGH

The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with …

Sep 4, 2026
CVE-2026-85085
9.6 CRITICAL

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded …

Sep 4, 2026
CVE-2026-84146
5.3 MEDIUM

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product …

Sep 4, 2026
CVE-2026-84066
3.1 LOW

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified …

Sep 4, 2026
CVE-2026-82194
5.5 MEDIUM

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion …

Sep 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.