CVE Database

114851+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9187
5.3 MEDIUM

The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due …

Jun 16, 2026
CVE-2026-8443
8.8 HIGH

The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' parameters of the wppro_get_overall_chart_data AJAX action in …

Jun 16, 2026
CVE-2026-6933
8.8 HIGH

The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in versions up to and including 2.0. This is …

Jun 16, 2026
CVE-2026-5149
6.5 MEDIUM

The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 This is due to the get_submission_content AJAX …

Jun 16, 2026
CVE-2026-50255
6.7 MEDIUM

Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed …

Jun 16, 2026
CVE-2026-10780
4.3 MEDIUM

The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to …

Jun 16, 2026
CVE-2026-10635
6.3 MEDIUM

On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintains a global list, xtensa_domain_list, of active memory domains using a list node embedded …

Jun 16, 2026
CVE-2025-10262
6.3 MEDIUM

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user …

Jun 16, 2026
CVE-2026-6964
5.3 MEDIUM

The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to …

Jun 16, 2026
CVE-2026-7273
8.8 HIGH

A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the …

Jun 16, 2026
CVE-2026-42014
6.6 MEDIUM

A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can lead to a use-after-free vulnerability. This occurs when …

Jun 16, 2026
CVE-2026-1767
5.6 MEDIUM

A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow …

Jun 16, 2026
CVE-2026-1766
5.6 MEDIUM

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when …

Jun 16, 2026
CVE-2026-1765
5.6 MEDIUM

A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This vulnerability, a heap buffer overflow, occurs when processing specially …

Jun 16, 2026
CVE-2026-1764
5.6 MEDIUM

A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds …

Jun 16, 2026
CVE-2026-12162
5.5 MEDIUM

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via …

Jun 16, 2026
CVE-2026-12161
8.8 HIGH

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify …

Jun 16, 2026
CVE-2026-9262
6.5 MEDIUM

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9261
6.8 MEDIUM

Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9260
6.2 MEDIUM

Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9259
6.5 MEDIUM

Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-9258
6.5 MEDIUM

Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Jun 16, 2026
CVE-2026-53430

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. …

Jun 15, 2026
CVE-2026-48854

Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming …

Jun 15, 2026
CVE-2026-48853

Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via …

Jun 15, 2026
CVE-2026-48723
7.8 HIGH

The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via …

Jun 15, 2026
CVE-2026-48599

Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting …

Jun 15, 2026
CVE-2026-12205
9.1 CRITICAL

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object …

Jun 15, 2026
CVE-2026-5064

Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial …

Jun 15, 2026
CVE-2026-48714
9.1 CRITICAL

i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the …

Jun 15, 2026
CVE-2026-48713
9.1 CRITICAL

Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed …

Jun 15, 2026
CVE-2026-48157
6.1 MEDIUM

Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses …

Jun 15, 2026
CVE-2026-48017
8.8 HIGH

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into …

Jun 15, 2026
CVE-2026-12087
9.1 CRITICAL

Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is …

Jun 15, 2026
CVE-2026-11832
9.1 CRITICAL

Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which …

Jun 15, 2026
CVE-2026-9691
9.8 CRITICAL

Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

Jun 15, 2026
CVE-2026-52703
9.6 CRITICAL

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

Jun 15, 2026
CVE-2026-52702
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.

Jun 15, 2026
CVE-2026-52700
8.5 HIGH

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

Jun 15, 2026
CVE-2026-52699
7.5 HIGH

Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.

Jun 15, 2026
CVE-2026-52697
8.5 HIGH

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

Jun 15, 2026
CVE-2026-52695
7.5 HIGH

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

Jun 15, 2026
CVE-2026-52694
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

Jun 15, 2026
CVE-2026-52693
9.3 CRITICAL

Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

Jun 15, 2026
CVE-2026-52692
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

Jun 15, 2026
CVE-2026-49781
9.8 CRITICAL

Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

Jun 15, 2026
CVE-2026-49780
8.8 HIGH

Customer Privilege Escalation in Dokan <= 5.0.2 versions.

Jun 15, 2026
CVE-2026-49776
9.3 CRITICAL

Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.

Jun 15, 2026
CVE-2026-49775
6.5 MEDIUM

Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions.

Jun 15, 2026
CVE-2026-49773
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions.

Jun 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.