CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-84960
6.1 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 …

Sep 11, 2026
CVE-2026-7438
6.4 MEDIUM

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all …

Sep 11, 2026
CVE-2026-78172
6.1 MEDIUM

The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and …

Sep 11, 2026
CVE-2026-77150
6.1 MEDIUM

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 …

Sep 11, 2026
CVE-2026-19985
6.1 MEDIUM

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', …

Sep 11, 2026
CVE-2026-18964
6.1 MEDIUM

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected …

Sep 11, 2026
CVE-2026-18562
6.1 MEDIUM

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions …

Sep 11, 2026
CVE-2026-12215
5.3 MEDIUM

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, …

Sep 11, 2026
CVE-2026-11496
6.5 MEDIUM

The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Sep 11, 2026
CVE-2026-11446
5.3 MEDIUM

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, …

Sep 11, 2026
CVE-2026-78135
5.6 MEDIUM

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

Sep 11, 2026
CVE-2026-89145
4.2 MEDIUM

Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to …

Sep 11, 2026
CVE-2026-89092
4.2 MEDIUM

The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large …

Sep 11, 2026
CVE-2026-88914
4.4 MEDIUM

A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow …

Sep 11, 2026
CVE-2026-78129
5.9 MEDIUM

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

Sep 11, 2026
CVE-2026-78126
5.9 MEDIUM

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

Sep 11, 2026
CVE-2026-78123
5.9 MEDIUM

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

Sep 11, 2026
CVE-2026-86087
4.3 MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on …

Sep 10, 2026
CVE-2026-79725
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

Sep 10, 2026
CVE-2026-79723
5.0 MEDIUM

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

Sep 10, 2026
CVE-2026-79590
6.5 MEDIUM

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that …

Sep 10, 2026
CVE-2026-54054
6.5 MEDIUM

Transmute is a free, open-source, self-hosted file conversion and compression tool. Prior to version 1.3.0, Transmute's URL import endpoint, `POST /api/files/url`, is vulnerable to Server-Side …

Sep 10, 2026
CVE-2026-49838
5.9 MEDIUM

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during …

Sep 10, 2026
CVE-2026-49837
5.9 MEDIUM

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing …

Sep 10, 2026
CVE-2026-45767
4.4 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could …

Sep 10, 2026
CVE-2026-36392
5.4 MEDIUM

FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is …

Sep 10, 2026
CVE-2026-9667
5.3 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server …

Sep 10, 2026
CVE-2026-9327
6.3 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in …

Sep 10, 2026
CVE-2026-9225
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control …

Sep 10, 2026
CVE-2026-9176
6.7 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability …

Sep 10, 2026
CVE-2026-89089
6.5 MEDIUM

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run …

Sep 10, 2026
CVE-2026-45752
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when …

Sep 10, 2026
CVE-2026-45751
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's inspection-buffer helper could …

Sep 10, 2026
CVE-2026-3096
4.7 MEDIUM

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the …

Sep 10, 2026
CVE-2026-19596
5.9 MEDIUM

An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a …

Sep 10, 2026
CVE-2022-26962
5.4 MEDIUM

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. …

Sep 10, 2026
CVE-2026-9338
5.3 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit …

Sep 10, 2026
CVE-2026-9336
6.5 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. …

Sep 10, 2026
CVE-2026-88059
4.0 MEDIUM

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common …

Sep 10, 2026
CVE-2026-88035
4.7 MEDIUM

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and …

Sep 10, 2026
CVE-2026-88032
5.9 MEDIUM

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation …

Sep 10, 2026
CVE-2026-87107
5.4 MEDIUM

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported …

Sep 10, 2026
CVE-2026-87106
6.5 MEDIUM

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server …

Sep 10, 2026
CVE-2026-89045
4.0 MEDIUM

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values …

Sep 10, 2026
CVE-2026-89044
6.5 MEDIUM

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle …

Sep 10, 2026
CVE-2026-88055
5.5 MEDIUM

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the …

Sep 10, 2026
CVE-2026-88054
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack …

Sep 10, 2026
CVE-2026-88028
6.5 MEDIUM

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation …

Sep 10, 2026
CVE-2026-88026
6.5 MEDIUM

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a …

Sep 10, 2026
CVE-2026-88050
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.