CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-80595

In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - add response length checks The driver processes response data from device buffers …

Aug 28, 2026
CVE-2026-80594

In the Linux kernel, the following vulnerability has been resolved: Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing The driver parses …

Aug 28, 2026
CVE-2026-80593
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (asus_atk0110) Check package count before accessing element atk_ec_present() walks the management group package returned …

Aug 28, 2026
CVE-2026-80592

In the Linux kernel, the following vulnerability has been resolved: samples/damon/mtier: fail early if address range parameters are invalid The comment on top of `struct …

Aug 28, 2026
CVE-2026-80591
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix listxattr handling of corrupted xattr entries Validate the xattr entry before reading its …

Aug 28, 2026
CVE-2026-80590
8.6 HIGH

In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before reassembly A virtio_net_hdr (tun/tap, or AF_PACKET with …

Aug 28, 2026
CVE-2026-79996
7.2 HIGH

The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have …

Aug 28, 2026
CVE-2026-79995
4.3 MEDIUM

The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the …

Aug 28, 2026
CVE-2026-79706
5.3 MEDIUM

The Breeze Cache WordPress plugin before 2.5.13 does not sanitise a value taken from the request before using it to build the paths of the …

Aug 28, 2026
CVE-2026-79615
2.7 LOW

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.4 does not check authorisation when returning question bank entries through one of its REST API …

Aug 28, 2026
CVE-2026-78238
5.4 MEDIUM

SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to …

Aug 28, 2026
CVE-2026-78032
9.8 CRITICAL

SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.

Aug 28, 2026
CVE-2026-77838
5.4 MEDIUM

SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to …

Aug 28, 2026
CVE-2026-77701
5.3 MEDIUM

The WCFM Marketplace WordPress plugin before 3.8.2 does not correctly verify that the person requesting a refund owns the order, allowing unauthenticated users to create …

Aug 28, 2026
CVE-2026-76581
9.8 CRITICAL

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent …

Aug 28, 2026
CVE-2026-73827
5.4 MEDIUM

SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who is logging in to …

Aug 28, 2026
CVE-2026-6286
7.2 HIGH

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up …

Aug 28, 2026
CVE-2026-5097
7.5 HIGH

The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is …

Aug 28, 2026
CVE-2026-4246
6.1 MEDIUM

The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 's' parameter of the Advanced Search REST endpoint in all versions …

Aug 28, 2026
CVE-2026-40541
9.0 CRITICAL

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, …

Aug 28, 2026
CVE-2026-19423
8.1 HIGH

The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form …

Aug 28, 2026
CVE-2026-19084
7.5 HIGH

The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files …

Aug 28, 2026
CVE-2026-14567
5.3 MEDIUM

The User Frontend WordPress plugin before 4.3.10 does not restrict access to its user directory search endpoint, allowing unauthenticated attackers to retrieve the email address …

Aug 28, 2026
CVE-2026-14558
7.2 HIGH

The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users …

Aug 28, 2026
CVE-2026-12514
5.3 MEDIUM

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.70 do not perform a capability check in their file-upload handler, which is registered …

Aug 28, 2026
CVE-2026-12513
6.8 MEDIUM

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly sanitize a file path taken from a frontend file submission …

Aug 28, 2026
CVE-2026-82090

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge …

Aug 28, 2026
CVE-2026-82089

The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.

Aug 28, 2026
CVE-2026-82082
9.8 CRITICAL

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

Aug 28, 2026
CVE-2026-82081
6.4 MEDIUM

wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

Aug 28, 2026
CVE-2026-77365
7.2 HIGH

The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored …

Aug 28, 2026
CVE-2026-76053
7.2 HIGH

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser …

Aug 28, 2026
CVE-2026-3129
6.4 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted `<img>` tag attributes in all versions up to, and including, 7.7. …

Aug 28, 2026
CVE-2026-18983
7.5 HIGH

The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 …

Aug 28, 2026
CVE-2026-18978
7.2 HIGH

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to …

Aug 28, 2026
CVE-2026-18324
7.2 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field …

Aug 28, 2026
CVE-2026-16759
6.5 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited to zero-argument function invocation in all …

Aug 28, 2026
CVE-2026-16654
6.4 MEDIUM

The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'size' Shortcode Attribute in all versions up to, and including, 3.15.6 …

Aug 28, 2026
CVE-2026-15798
6.4 MEDIUM

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'slider' Block Attribute in all versions up to, and including, 3.5.1.38 …

Aug 28, 2026
CVE-2026-78618

A business logic flaw in WatchGuard Dimension allows an authenticated administrator to trigger multiple backend operations within a single logical flow by sending a specially …

Aug 28, 2026
CVE-2026-78617

WatchGuard Dimension's web login endpoint does not enforce effective rate-limiting or account lockout by default allowing a remote attacker to perform automated password guessing against …

Aug 28, 2026
CVE-2026-78616

A Stored Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's Trusted CA certificate configuration allows an authenticated administrator to execute arbitrary JavaScript in another authenticated administrator's …

Aug 28, 2026
CVE-2026-78615

A Reflected Cross-Site Scripting (XSS) vulnerability in WatchGuard Dimension's report detail page allows an attacker to execute arbitrary JavaScript in a authenticated user's browser with …

Aug 28, 2026
CVE-2026-78614

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the audit report feature which allows an authenticated user with report administration permissions gain arbitrary command …

Aug 28, 2026
CVE-2026-78613

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the log viewer feature which allows an authenticated user with report administration permissions gain arbitrary command …

Aug 28, 2026
CVE-2026-78612

WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature which allows an authenticated user with report administration permissions gain arbitrary command …

Aug 28, 2026
CVE-2026-78610

WatchGuard Dimension's Web UI exposes an administrator passphrase change action that lacks CSRF protection. An attacker who can induce an authenticated global administrator's browser to …

Aug 28, 2026
CVE-2026-78500

A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent …

Aug 28, 2026
CVE-2026-78499

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension FTP Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network …

Aug 28, 2026
CVE-2026-78498

A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.