CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-51610
4.3 MEDIUM

Incorrect access control in the RebootSystem function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force an immediate reboot via sending a crafted POST …

Aug 28, 2026
CVE-2026-51376
6.5 MEDIUM

An issue in BitChat for iOS v1.15.0 allows a remote attacker to cause a denial of service via an unauthenticated MESSAGE packet into the mesh …

Aug 28, 2026
CVE-2026-50980
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the DNS lookup/management component of oPanel before v1.20.25 allows remote attackers to execute arbitrary JavaScript and perform session hijacking via …

Aug 28, 2026
CVE-2026-39071
5.4 MEDIUM

WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contributor) …

Aug 28, 2026
CVE-2026-39070
4.8 MEDIUM

WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit …

Aug 28, 2026
CVE-2026-82330
6.1 MEDIUM

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly …

Aug 28, 2026
CVE-2026-82328
6.1 MEDIUM

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the …

Aug 28, 2026
CVE-2026-82327
5.5 MEDIUM

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache …

Aug 28, 2026
CVE-2026-82324
6.1 MEDIUM

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate …

Aug 28, 2026
CVE-2026-82227
8.5 HIGH

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

Aug 28, 2026
CVE-2026-82220
5.3 MEDIUM

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

Aug 28, 2026
CVE-2026-82181
5.5 MEDIUM

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history …

Aug 28, 2026
CVE-2026-82112
3.5 LOW

A flaw has been found in houtini-ai houtini-lm up to 2.13.2. The impacted element is an unknown function of the file src/index.ts of the component …

Aug 28, 2026
CVE-2026-82078
9.1 CRITICAL KEV

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based …

Aug 28, 2026
CVE-2026-81767
7.5 HIGH

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

Aug 28, 2026
CVE-2026-81761
4.3 MEDIUM

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

Aug 28, 2026
CVE-2026-81760
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.

Aug 28, 2026
CVE-2026-81759
5.4 MEDIUM

Contributor Broken Access Control in WpEvently <= 5.5.0 versions.

Aug 28, 2026
CVE-2026-81757
7.2 HIGH

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

Aug 28, 2026
CVE-2026-81578
9.8 CRITICAL KEV

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative …

Aug 28, 2026
CVE-2026-81341
6.5 MEDIUM

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence …

Aug 28, 2026
CVE-2026-81299
4.3 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

Aug 28, 2026
CVE-2026-81285
7.5 HIGH

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

Aug 28, 2026
CVE-2026-81284
4.3 MEDIUM

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

Aug 28, 2026
CVE-2026-81020
7.4 HIGH

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a …

Aug 28, 2026
CVE-2026-81019
7.4 HIGH

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a …

Aug 28, 2026
CVE-2026-75758

Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM …

Aug 28, 2026
CVE-2026-6176
7.2 HIGH

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and …

Aug 28, 2026
CVE-2026-5953
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: …

Aug 28, 2026
CVE-2026-5934
7.2 HIGH

The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input …

Aug 28, 2026
CVE-2026-5800
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue …

Aug 28, 2026
CVE-2026-5096
5.3 MEDIUM

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the …

Aug 28, 2026
CVE-2026-58107

CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store …

Aug 28, 2026
CVE-2026-58106

CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, …

Aug 28, 2026
CVE-2026-56854
7.5 HIGH

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for …

Aug 28, 2026
CVE-2026-50979
8.1 HIGH

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the …

Aug 28, 2026
CVE-2026-4378
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects …

Aug 28, 2026
CVE-2026-3423
6.4 MEDIUM

The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, …

Aug 28, 2026
CVE-2026-38725
5.4 MEDIUM

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input …

Aug 28, 2026
CVE-2026-38638
7.5 HIGH

An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-38636
7.5 HIGH

An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-38093
3.3 LOW

file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses …

Aug 28, 2026
CVE-2026-37751
9.8 CRITICAL

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.

Aug 28, 2026
CVE-2026-37736
7.5 HIGH

An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-37710
6.1 MEDIUM

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function

Aug 28, 2026
CVE-2026-37237
7.5 HIGH

vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py …

Aug 28, 2026
CVE-2026-37236

grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with …

Aug 28, 2026
CVE-2026-19412

This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical …

Aug 28, 2026
CVE-2026-15603
5.3 MEDIUM

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize …

Aug 28, 2026
CVE-2026-14942

Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.