CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82193
5.5 MEDIUM

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a …

Sep 4, 2026
CVE-2026-82186
4.1 MEDIUM

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with …

Sep 4, 2026
CVE-2026-81347
5.9 MEDIUM

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers …

Sep 4, 2026
CVE-2026-81270
7.5 HIGH

Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes …

Sep 4, 2026
CVE-2026-80438
5.9 MEDIUM

The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as …

Sep 4, 2026
CVE-2026-80181
9.1 CRITICAL

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, …

Sep 4, 2026
CVE-2026-80180
6.1 MEDIUM

Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, …

Sep 4, 2026
CVE-2026-79632
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification …

Sep 4, 2026
CVE-2026-79631
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, …

Sep 4, 2026
CVE-2026-79630
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was …

Sep 4, 2026
CVE-2026-74853
6.8 MEDIUM

The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above …

Sep 4, 2026
CVE-2026-71216
5.3 MEDIUM

PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a …

Sep 4, 2026
CVE-2026-70403
9.8 CRITICAL

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

Sep 4, 2026
CVE-2026-69657
9.8 CRITICAL

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

Sep 4, 2026
CVE-2026-66840
7.5 HIGH

XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.

Sep 4, 2026
CVE-2026-62928
9.8 CRITICAL

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

Sep 4, 2026
CVE-2026-19224
7.2 HIGH

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a …

Sep 4, 2026
CVE-2026-17517
5.3 MEDIUM

The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing …

Sep 4, 2026
CVE-2026-16281
7.1 HIGH

The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX …

Sep 4, 2026
CVE-2026-15354
9.8 CRITICAL

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization …

Sep 4, 2026
CVE-2025-15691
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying …

Sep 4, 2026
CVE-2026-84715
8.8 HIGH

FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with …

Sep 2, 2026
CVE-2026-84485
7.5 HIGH

APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers can …

Sep 2, 2026
CVE-2026-84484
7.5 HIGH

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV …

Sep 2, 2026
CVE-2026-84438
3.5 LOW

A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the …

Sep 2, 2026
CVE-2026-84437
3.5 LOW

A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation …

Sep 2, 2026
CVE-2026-84431
4.4 MEDIUM

A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a …

Sep 2, 2026
CVE-2026-82968
6.4 MEDIUM

A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their …

Sep 2, 2026
CVE-2026-84702
7.5 HIGH

facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in …

Sep 2, 2026
CVE-2026-84701
5.4 MEDIUM

NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers …

Sep 2, 2026
CVE-2026-84700
8.6 HIGH

PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client …

Sep 2, 2026
CVE-2026-84699
9.1 CRITICAL

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and …

Sep 2, 2026
CVE-2026-84698
6.5 MEDIUM

PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can …

Sep 2, 2026
CVE-2026-84697
5.3 MEDIUM

Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to …

Sep 2, 2026
CVE-2026-84696
8.2 HIGH

Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass …

Sep 2, 2026
CVE-2026-84695
8.7 HIGH

BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. …

Sep 2, 2026
CVE-2026-84694
8.8 HIGH

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell …

Sep 2, 2026
CVE-2026-84430
6.3 MEDIUM

A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal …

Sep 2, 2026
CVE-2026-84427
4.3 MEDIUM

A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing …

Sep 2, 2026
CVE-2026-84425
4.3 MEDIUM

A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing …

Sep 2, 2026
CVE-2026-84359

Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Sep 2, 2026
CVE-2026-84358

Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar …

Sep 2, 2026
CVE-2026-84357

Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted …

Sep 2, 2026
CVE-2026-84356

UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security …

Sep 2, 2026
CVE-2026-84355

Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy …

Sep 2, 2026
CVE-2026-84354

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via …

Sep 2, 2026
CVE-2026-84353

Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute …

Sep 2, 2026
CVE-2026-84352

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox …

Sep 2, 2026
CVE-2026-84351

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute …

Sep 2, 2026
CVE-2026-84350

Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Sep 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.