CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87797
4.3 MEDIUM

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one …

Sep 12, 2026
CVE-2026-86790
6.8 MEDIUM

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, …

Sep 12, 2026
CVE-2026-84024
4.3 MEDIUM

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration …

Sep 12, 2026
CVE-2026-84023
6.5 MEDIUM

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify …

Sep 12, 2026
CVE-2026-83532
6.8 MEDIUM

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with …

Sep 12, 2026
CVE-2026-82847
6.8 MEDIUM

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, …

Sep 12, 2026
CVE-2026-78152
5.3 MEDIUM

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by …

Sep 12, 2026
CVE-2026-77753
5.5 MEDIUM

The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one …

Sep 12, 2026
CVE-2026-77689
5.3 MEDIUM

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as …

Sep 12, 2026
CVE-2026-90467
4.0 MEDIUM

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command …

Sep 12, 2026
CVE-2026-89268
5.4 MEDIUM

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce …

Sep 12, 2026
CVE-2026-89267
4.3 MEDIUM

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. …

Sep 12, 2026
CVE-2026-90461
6.3 MEDIUM

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

Sep 11, 2026
CVE-2026-54258
6.5 MEDIUM

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` …

Sep 11, 2026
CVE-2026-54248
6.5 MEDIUM

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw …

Sep 11, 2026
CVE-2026-50018
6.5 MEDIUM

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint …

Sep 11, 2026
CVE-2026-48496
6.2 MEDIUM

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged …

Sep 11, 2026
CVE-2026-49439
4.3 MEDIUM

OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. …

Sep 11, 2026
CVE-2026-45057
4.9 MEDIUM

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when …

Sep 11, 2026
CVE-2026-89332
5.5 MEDIUM

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors …

Sep 11, 2026
CVE-2026-79035
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context …

Sep 11, 2026
CVE-2026-77490
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Sep 11, 2026
CVE-2026-49463
6.5 MEDIUM

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version …

Sep 11, 2026
CVE-2026-49462
5.3 MEDIUM

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and …

Sep 11, 2026
CVE-2026-89329
6.2 MEDIUM

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands …

Sep 11, 2026
CVE-2026-81910
6.5 MEDIUM

Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color …

Sep 11, 2026
CVE-2026-62140
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Quiz And Survey Master <= 11.2.5 versions.

Sep 11, 2026
CVE-2026-62139
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

Sep 11, 2026
CVE-2026-62138
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.

Sep 11, 2026
CVE-2026-62137
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in bbPress <= 2.6.14 versions.

Sep 11, 2026
CVE-2026-62136
5.3 MEDIUM

Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.

Sep 11, 2026
CVE-2026-62135
5.3 MEDIUM

Unauthenticated Broken Access Control in Booktics <= 1.0.24 versions.

Sep 11, 2026
CVE-2026-62134
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions.

Sep 11, 2026
CVE-2026-62133
5.4 MEDIUM

Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.

Sep 11, 2026
CVE-2026-62132
5.3 MEDIUM

Subscriber Broken Access Control in Masteriyo - LMS <= 3.4.0 versions.

Sep 11, 2026
CVE-2026-62114
5.3 MEDIUM

Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.

Sep 11, 2026
CVE-2026-62113
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Slim SEO <= 4.10.0 versions.

Sep 11, 2026
CVE-2026-62111
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Simple Payment <= 2.5.4 versions.

Sep 11, 2026
CVE-2026-62110
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Bold Page Builder <= 5.9.9 versions.

Sep 11, 2026
CVE-2026-62088
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

Sep 11, 2026
CVE-2026-27378
5.3 MEDIUM

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

Sep 11, 2026
CVE-2026-9160
4.3 MEDIUM

Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website …

Sep 11, 2026
CVE-2026-89090
5.9 MEDIUM

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to …

Sep 11, 2026
CVE-2026-82535
6.1 MEDIUM

Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by …

Sep 11, 2026
CVE-2026-7298
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue …

Sep 11, 2026
CVE-2026-18495
6.1 MEDIUM

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF …

Sep 11, 2026
CVE-2026-18061
5.9 MEDIUM

Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access …

Sep 11, 2026
CVE-2026-8304
5.5 MEDIUM

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus About: …

Sep 11, 2026
CVE-2026-89265
4.3 MEDIUM

MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office …

Sep 11, 2026
CVE-2026-89264
4.3 MEDIUM

MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other …

Sep 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.