CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-8614
4.3 MEDIUM

The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin_delete_assistio_settings() …

Jun 24, 2026
CVE-2026-7617
5.3 MEDIUM

The Secufor_OAuth plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.7. This is due to the plugin not …

Jun 24, 2026
CVE-2026-6292
4.3 MEDIUM

The MP Customize Login Page plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in all versions up to and including 1.0. This is …

Jun 24, 2026
CVE-2026-4297
8.8 HIGH

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to …

Jun 24, 2026
CVE-2026-13006

ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.35 in Java applications, allows an attacker to execute arbitrary …

Jun 24, 2026
CVE-2026-12417
9.8 CRITICAL

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, …

Jun 24, 2026
CVE-2026-12416
9.8 CRITICAL

The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, and including, 1.0.0. This is due …

Jun 24, 2026
CVE-2026-12100
7.2 HIGH

The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0 via the 'url' parameter. This …

Jun 24, 2026
CVE-2026-12095
7.2 HIGH

The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2 via the 'api_url' parameter. This …

Jun 24, 2026
CVE-2026-12094
5.3 MEDIUM

The Advanced Contact Form 7 - Compact DB plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on …

Jun 24, 2026
CVE-2026-11997
4.3 MEDIUM

The Bulk SEO Image plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1. This is due to missing …

Jun 24, 2026
CVE-2026-11370
6.4 MEDIUM

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. …

Jun 24, 2026
CVE-2026-10753
2.7 LOW

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have …

Jun 24, 2026
CVE-2026-10749
7.2 HIGH

The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's …

Jun 24, 2026
CVE-2026-10735
7.5 HIGH

Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress …

Jun 24, 2026
CVE-2026-10552
4.3 MEDIUM

The Blue Captcha plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 2.0.1. This is due to missing or …

Jun 24, 2026
CVE-2026-10531
5.4 MEDIUM

The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, …

Jun 24, 2026
CVE-2026-10092
7.2 HIGH

The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortcode in Post Comments in all versions up …

Jun 24, 2026
CVE-2026-10091
7.2 HIGH

The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, …

Jun 24, 2026
CVE-2026-12569
KEV

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization …

Jun 18, 2026
CVE-2026-48768
9.3 CRITICAL

TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object …

Jun 18, 2026
CVE-2026-48764
8.2 HIGH

TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname once and checking whether the resolved …

Jun 18, 2026
CVE-2026-54533

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, malicious algorithms can potentially access other algorithms input and output files. Version …

Jun 17, 2026
CVE-2026-54445

vantage6 is an open-source infrastructure for privacy preserving analysis. Versions prior to 5.0.0 provide an initial user with username `root` and password `root`. This is …

Jun 17, 2026
CVE-2026-53676
7.2 HIGH

ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to …

Jun 17, 2026
CVE-2026-50268
1.9 LOW

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Encryption 4.0.0 through 4.1.0, configuring `encrypt:rsa:algorithm=OAEP` …

Jun 17, 2026
CVE-2026-50267
4.7 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL …

Jun 17, 2026
CVE-2026-50202
5.9 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Security.Authentication.CloudFoundryBase prior to version 3.4.0, Steeltoe.Security.Authentication.JwtBearer …

Jun 17, 2026
CVE-2026-50201
6.5 MEDIUM

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and …

Jun 17, 2026
CVE-2026-48759
7.1 HIGH

TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability through cross-workspace Theme Template modification and deletion. The …

Jun 17, 2026
CVE-2026-45617
7.5 HIGH

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing …

Jun 17, 2026
CVE-2026-45357
7.5 HIGH

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime implementation parses width specifiers …

Jun 17, 2026
CVE-2026-44646
5.3 MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, Context.spawn() creates a child Context for the {% …

Jun 17, 2026
CVE-2026-44645
6.5 MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the renderLimit option can be fully bypassed by …

Jun 17, 2026
CVE-2026-44644
6.1 MEDIUM

LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are vulnerable to XSS through a flaw in the …

Jun 17, 2026
CVE-2026-12568
6.5 MEDIUM

The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has …

Jun 17, 2026
CVE-2026-12567
2.2 LOW

The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a …

Jun 17, 2026
CVE-2026-12566
3.1 LOW

The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authentication endpoint without validation. An attacker in a man-in-the-middle …

Jun 17, 2026
CVE-2026-12565
5.3 MEDIUM

The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, relying entirely on the behavior of external tools (e.g. GNU …

Jun 17, 2026
CVE-2024-27928

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, if an attacker hacks into a vantage6 user's email account, they can …

Jun 17, 2026
CVE-2024-24769

vantage6 is an open-source infrastructure for privacy preserving analysis. Prior to version 5.0.0, users can reset their MFA token via API routes that send them …

Jun 17, 2026
CVE-2026-8050

In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer without first verifying that it is non-NULL. Sending an …

Jun 17, 2026
CVE-2026-8049

In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly …

Jun 17, 2026
CVE-2026-54386
6.1 MEDIUM

marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping …

Jun 17, 2026
CVE-2026-50200
7.5 HIGH

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and …

Jun 17, 2026
CVE-2026-50196
7.5 HIGH

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Discovery.Eureka prior to versions 4.2.0 and …

Jun 17, 2026
CVE-2026-50194
8.2 HIGH

Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through …

Jun 17, 2026
CVE-2026-48997
7.1 HIGH

e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ImageMagick resize destination path. In resize_image(), the …

Jun 17, 2026
CVE-2026-48991
5.5 MEDIUM

XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts could be exposed during a user-initiated login under certain local …

Jun 17, 2026
CVE-2026-48990
5.3 MEDIUM

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts …

Jun 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.