CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82224
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.

Aug 31, 2026
CVE-2026-82221
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

Aug 31, 2026
CVE-2026-81892
8.1 HIGH

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single …

Aug 31, 2026
CVE-2026-81891
8.1 HIGH

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the …

Aug 31, 2026
CVE-2026-81890
5.4 MEDIUM

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in …

Aug 31, 2026
CVE-2026-81889
8.6 HIGH

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side …

Aug 31, 2026
CVE-2026-81888
5.4 MEDIUM

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is …

Aug 31, 2026
CVE-2026-81887

Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the …

Aug 31, 2026
CVE-2026-81780
10.0 CRITICAL

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

Aug 31, 2026
CVE-2026-81779
10.0 CRITICAL

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through …

Aug 31, 2026
CVE-2026-81778
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.

Aug 31, 2026
CVE-2026-81768
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.

Aug 31, 2026
CVE-2026-81765
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.

Aug 31, 2026
CVE-2026-81764
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.

Aug 31, 2026
CVE-2026-81763
9.3 CRITICAL

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

Aug 31, 2026
CVE-2026-81762
6.5 MEDIUM

Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.

Aug 31, 2026
CVE-2026-81758
6.3 MEDIUM

Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.

Aug 31, 2026
CVE-2026-81756
9.3 CRITICAL

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

Aug 31, 2026
CVE-2026-81298
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.

Aug 31, 2026
CVE-2026-81297
7.5 HIGH

Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Aug 31, 2026
CVE-2026-81296
7.5 HIGH

Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Aug 31, 2026
CVE-2026-81293
9.3 CRITICAL

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

Aug 31, 2026
CVE-2026-81291
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

Aug 31, 2026
CVE-2026-81290
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.

Aug 31, 2026
CVE-2026-81287
8.5 HIGH

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

Aug 31, 2026
CVE-2026-81280
6.5 MEDIUM

Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

Aug 31, 2026
CVE-2026-81278
5.4 MEDIUM

Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.

Aug 31, 2026
CVE-2026-79483
5.3 MEDIUM

FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators …

Aug 31, 2026
CVE-2026-79408
9.8 CRITICAL

An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

Aug 31, 2026
CVE-2026-79407
7.5 HIGH

A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() …

Aug 31, 2026
CVE-2026-75594

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to …

Aug 31, 2026
CVE-2026-75592

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks …

Aug 31, 2026
CVE-2026-75460
6.5 MEDIUM

XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully …

Aug 31, 2026
CVE-2026-75458
8.1 HIGH

The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID …

Aug 31, 2026
CVE-2026-71415

Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload …

Aug 31, 2026
CVE-2026-62993

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release …

Aug 31, 2026
CVE-2026-61641
8.1 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an …

Aug 31, 2026
CVE-2026-61640

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with …

Aug 31, 2026
CVE-2026-61639

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads …

Aug 31, 2026
CVE-2026-61638

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. …

Aug 31, 2026
CVE-2026-54600

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — …

Aug 31, 2026
CVE-2026-54599

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the …

Aug 31, 2026
CVE-2026-54598
7.5 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any …

Aug 31, 2026
CVE-2026-54179
4.4 MEDIUM

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 …

Aug 31, 2026
CVE-2026-50199
4.3 MEDIUM

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential …

Aug 31, 2026
CVE-2026-50198
4.3 MEDIUM

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to …

Aug 31, 2026
CVE-2026-38577
9.8 CRITICAL

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.

Aug 31, 2026
CVE-2025-63607
6.1 MEDIUM

TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of …

Aug 31, 2026
CVE-2026-82905
6.3 MEDIUM

A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The …

Aug 31, 2026
CVE-2026-82835
5.4 MEDIUM

A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.