CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82462
6.5 MEDIUM

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token validation. Attackers can substitute access tokens minted for …

Aug 29, 2026
CVE-2026-82461
8.1 HIGH

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens …

Aug 29, 2026
CVE-2026-82460
9.8 CRITICAL

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use …

Aug 29, 2026
CVE-2026-82481

The cohttp package before 6.3.0 for OCaml allows directory traversal.

Aug 29, 2026
CVE-2026-82477
5.8 MEDIUM

In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF issue allows remote attackers to access internal network resources via the Tenable proxy endpoint. …

Aug 29, 2026
CVE-2026-82457
7.8 HIGH

su-exec through 0.3 fails to validate numeric user and group identifiers parsed with strtol before assigning to uid_t and gid_t, allowing truncation of out-of-range values …

Aug 29, 2026
CVE-2026-82456
10.0 CRITICAL

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can …

Aug 29, 2026
CVE-2026-82455
7.1 HIGH

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction …

Aug 29, 2026
CVE-2026-82454
9.1 CRITICAL

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' …

Aug 29, 2026
CVE-2026-82453
7.5 HIGH

rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing …

Aug 29, 2026
CVE-2026-82452
9.8 CRITICAL

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, …

Aug 29, 2026
CVE-2026-82451
6.1 MEDIUM

Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer …

Aug 29, 2026
CVE-2026-82450
8.8 HIGH

BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions …

Aug 29, 2026
CVE-2026-82449
5.3 MEDIUM

Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response …

Aug 29, 2026
CVE-2026-82448
9.8 CRITICAL

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching …

Aug 29, 2026
CVE-2026-82447
8.8 HIGH

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed …

Aug 29, 2026
CVE-2026-14494
9.8 CRITICAL

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. …

Aug 29, 2026
CVE-2026-82364
4.2 MEDIUM

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order …

Aug 29, 2026
CVE-2026-80725

In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond …

Aug 29, 2026
CVE-2026-81346
4.3 MEDIUM

The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, …

Aug 29, 2026
CVE-2026-81342
4.7 MEDIUM

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers …

Aug 29, 2026
CVE-2026-81200
2.7 LOW

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to …

Aug 29, 2026
CVE-2026-81026
4.8 MEDIUM

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the …

Aug 29, 2026
CVE-2026-80488
4.1 MEDIUM

The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, …

Aug 29, 2026
CVE-2026-80311
4.3 MEDIUM

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the …

Aug 29, 2026
CVE-2026-77786
4.9 MEDIUM

The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires …

Aug 29, 2026
CVE-2026-77704
2.7 LOW

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change …

Aug 29, 2026
CVE-2026-77012
9.3 CRITICAL

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does …

Aug 29, 2026
CVE-2026-77010
6.5 MEDIUM

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently …

Aug 29, 2026
CVE-2026-77008
6.5 MEDIUM

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated …

Aug 29, 2026
CVE-2026-77007
7.5 HIGH

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing …

Aug 29, 2026
CVE-2026-76586
7.5 HIGH

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for …

Aug 29, 2026
CVE-2026-76548
8.2 HIGH

The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. …

Aug 29, 2026
CVE-2026-76547
6.6 MEDIUM

The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege …

Aug 29, 2026
CVE-2026-76546
6.8 MEDIUM

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as …

Aug 29, 2026
CVE-2026-19430
5.3 MEDIUM

The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content …

Aug 29, 2026
CVE-2026-18234
6.5 MEDIUM

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does …

Aug 29, 2026
CVE-2026-18233
6.5 MEDIUM

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing …

Aug 29, 2026
CVE-2026-17522
5.4 MEDIUM

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted …

Aug 29, 2026
CVE-2026-17520
4.8 MEDIUM

The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing …

Aug 29, 2026
CVE-2026-16947
9.1 CRITICAL

The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification …

Aug 29, 2026
CVE-2026-16600
7.7 HIGH

The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL …

Aug 29, 2026
CVE-2026-16259
9.8 CRITICAL

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and …

Aug 29, 2026
CVE-2026-16061
8.6 HIGH

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes …

Aug 29, 2026
CVE-2026-10522

The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register …

Aug 29, 2026
CVE-2026-41012
7.7 HIGH

Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials …

Aug 29, 2026
CVE-2026-55867

Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java …

Aug 28, 2026
CVE-2026-55860
5.9 MEDIUM

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport …

Aug 28, 2026
CVE-2026-55859
5.9 MEDIUM

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption …

Aug 28, 2026
CVE-2026-55858
5.9 MEDIUM

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.