CVE Database

47191+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-49052
4.3 MEDIUM

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from …

May 27, 2026
CVE-2026-49051
4.3 MEDIUM

Missing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Meta and …

May 27, 2026
CVE-2026-49047
4.3 MEDIUM

Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DearFlip: from n/a through 2.4.27.

May 27, 2026
CVE-2026-49045
4.3 MEDIUM

Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Adminimize: from n/a through 1.11.11.

May 27, 2026
CVE-2026-49044
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advanced Custom Fields: Font Awesome Field allows Stored XSS. This issue …

May 27, 2026
CVE-2026-48973
4.3 MEDIUM

Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SVG Support: from n/a through 2.5.14.

May 27, 2026
CVE-2026-48927
5.5 MEDIUM

Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to …

May 27, 2026
CVE-2026-48926
4.3 MEDIUM

Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials …

May 27, 2026
CVE-2026-48925
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attackers to attackers to trigger a build for a pull …

May 27, 2026
CVE-2026-48924
4.3 MEDIUM

Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

May 27, 2026
CVE-2026-48923
4.3 MEDIUM

Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect …

May 27, 2026
CVE-2026-48919
6.6 MEDIUM

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

May 27, 2026
CVE-2026-48918
6.6 MEDIUM

Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

May 27, 2026
CVE-2026-48917
6.6 MEDIUM

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.

May 27, 2026
CVE-2026-48916
6.6 MEDIUM

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.

May 27, 2026
CVE-2026-48545
6.8 MEDIUM

Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client …

May 27, 2026
CVE-2026-47119
6.1 MEDIUM

Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG …

May 27, 2026
CVE-2026-47118
6.5 MEDIUM

Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image …

May 27, 2026
CVE-2026-45571
5.4 MEDIUM

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted …

May 27, 2026
CVE-2026-44972
5.0 MEDIUM

GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in …

May 27, 2026
CVE-2026-30498
6.3 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.

May 27, 2026
CVE-2026-1248
4.3 MEDIUM

IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.

May 27, 2026
CVE-2026-9704
6.8 MEDIUM

A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) …

May 27, 2026
CVE-2026-9617
6.8 MEDIUM

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. …

May 27, 2026
CVE-2026-9035
6.5 MEDIUM

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM …

May 27, 2026
CVE-2026-8405
6.5 MEDIUM

IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug …

May 27, 2026
CVE-2026-7254
5.3 MEDIUM

IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.

May 27, 2026
CVE-2026-6938
6.5 MEDIUM

IBM Db2 12.1.0 through 12.1.4 is vulnerable to authorization bypass when uploading to a remote object storage path with a special query.

May 27, 2026
CVE-2026-6936
6.5 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a denial-of-service attack due to uncontrolled recursion in the Integrated Language Environment (ILE) compiler. An …

May 27, 2026
CVE-2026-6053
5.5 MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when a specially crafted query is run with range …

May 27, 2026
CVE-2026-6052
6.5 MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to running out of memory when executing certain queries with MDC tables.

May 27, 2026
CVE-2026-6051
5.5 MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service when executing a specially crafted query with a small …

May 27, 2026
CVE-2026-5516
4.4 MEDIUM

IBM WebSphere Application Server - Liberty 22.0.0.11 through 26.0.0.5 IBM WebSphere Application Server Liberty could allow a remote attacker to bypass security under limited conditions …

May 27, 2026
CVE-2026-5515
5.5 MEDIUM

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

May 27, 2026
CVE-2026-4410
4.8 MEDIUM

IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to …

May 27, 2026
CVE-2026-48971
4.3 MEDIUM

Missing Authorization vulnerability in WebToffee Product Import Export for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Product Import Export for …

May 27, 2026
CVE-2026-47104
4.0 MEDIUM

libusb before version 1.0.30 contains a one-byte out-of-bounds read vulnerability in parse_iad_array() in descriptor.c that allows attackers to trigger a denial of service by supplying …

May 27, 2026
CVE-2026-3676
6.5 MEDIUM

IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could …

May 27, 2026
CVE-2026-2607
5.1 MEDIUM

IBM MQ Operator SC2: v3.2.0 through 3.2.23CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1LTS: v2.0.0 …

May 27, 2026
CVE-2026-2340
6.5 MEDIUM

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a …

May 27, 2026
CVE-2026-23679
6.2 MEDIUM

libusb before version 1.0.30 contains a NULL pointer dereference vulnerability that allows attackers to crash applications by supplying a malformed USB configuration descriptor where an …

May 27, 2026
CVE-2025-3633
5.4 MEDIUM

IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows …

May 27, 2026
CVE-2024-40684
5.9 MEDIUM

IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2, and 1.3.8.0, 1.3.8.1, 1.3.8.2, 1.3.8.3, 1.3.8.4 IBM SmartCloud Analytics - …

May 27, 2026
CVE-2024-28765
5.3 MEDIUM

IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed …

May 27, 2026
CVE-2026-9689
4.2 MEDIUM

A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource …

May 27, 2026
CVE-2026-42751
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking Manager booking-manager allows Stored XSS.This issue affects Booking Manager: from n/a …

May 27, 2026
CVE-2026-42750
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nexcess WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through <= …

May 27, 2026
CVE-2026-42744
6.5 MEDIUM

Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Manipulating Hidden Fields.This issue affects Ads by WPQuads: …

May 27, 2026
CVE-2026-42732
6.5 MEDIUM

Improper Validation of Specified Quantity in Input vulnerability in Ads by WPQuads Ads by WPQuads quick-adsense-reloaded allows Input Data Manipulation.This issue affects Ads by WPQuads: …

May 27, 2026
CVE-2026-42726
6.5 MEDIUM

Missing Authorization vulnerability in Strategy11 Team AWP Classifieds another-wordpress-classifieds-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AWP Classifieds: from n/a through <= …

May 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.