CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-4559
6.4 MEDIUM

The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up …

Aug 22, 2026
CVE-2026-2996
7.5 HIGH

The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. …

Aug 22, 2026
CVE-2026-62382

PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously …

Aug 22, 2026
CVE-2026-62381
6.6 MEDIUM

luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For …

Aug 22, 2026
CVE-2026-62380
7.5 HIGH

Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) …

Aug 22, 2026
CVE-2026-62243
7.5 HIGH

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager …

Aug 22, 2026
CVE-2026-62204
6.6 MEDIUM

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing …

Aug 22, 2026
CVE-2026-60084
8.7 HIGH

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated …

Aug 22, 2026
CVE-2026-60083
4.9 MEDIUM

SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by …

Aug 22, 2026
CVE-2026-59809
4.9 MEDIUM

SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client …

Aug 22, 2026
CVE-2026-59808
8.8 HIGH

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts …

Aug 22, 2026
CVE-2026-59256
7.5 HIGH

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid …

Aug 22, 2026
CVE-2026-58003
7.1 HIGH

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can …

Aug 22, 2026
CVE-2026-58002
6.5 MEDIUM

WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by …

Aug 22, 2026
CVE-2026-58001
5.7 MEDIUM

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store …

Aug 22, 2026
CVE-2026-57998
7.8 HIGH

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without …

Aug 22, 2026
CVE-2026-57944
5.4 MEDIUM

AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to …

Aug 22, 2026
CVE-2026-56380
5.3 MEDIUM

AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public …

Aug 22, 2026
CVE-2026-4244
4.3 MEDIUM

The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all …

Aug 22, 2026
CVE-2026-11948

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 22, 2026
CVE-2026-11947

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 22, 2026
CVE-2026-77988
6.6 MEDIUM

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command …

Aug 22, 2026
CVE-2026-66917

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS …

Aug 22, 2026
CVE-2026-66916

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON …

Aug 22, 2026
CVE-2026-4245
4.3 MEDIUM

The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` …

Aug 22, 2026
CVE-2026-3424
5.3 MEDIUM

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up …

Aug 22, 2026
CVE-2026-77946
10.0 CRITICAL

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone …

Aug 22, 2026
CVE-2026-77945
7.4 HIGH

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of …

Aug 22, 2026
CVE-2026-78003
9.8 CRITICAL

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This …

Aug 22, 2026
CVE-2026-12710

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal …

Aug 22, 2026
CVE-2026-77002
9.8 CRITICAL

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users …

Aug 22, 2026
CVE-2026-77001
9.8 CRITICAL

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one …

Aug 22, 2026
CVE-2026-77000
9.8 CRITICAL

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating …

Aug 22, 2026
CVE-2026-76793
8.1 HIGH

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a …

Aug 22, 2026
CVE-2026-76789
8.8 HIGH

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and …

Aug 22, 2026
CVE-2026-19222
6.6 MEDIUM

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to …

Aug 22, 2026
CVE-2026-19221
7.2 HIGH

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a …

Aug 22, 2026
CVE-2026-19093
6.8 MEDIUM

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor …

Aug 22, 2026
CVE-2026-18052
8.1 HIGH

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an …

Aug 22, 2026
CVE-2026-16738
5.3 MEDIUM

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to …

Aug 22, 2026
CVE-2026-16612
5.3 MEDIUM

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected …

Aug 22, 2026
CVE-2026-16260
6.8 MEDIUM

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting …

Aug 22, 2026
CVE-2026-14187
2.7 LOW

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role …

Aug 22, 2026
CVE-2026-76074
4.3 MEDIUM

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions …

Aug 22, 2026
CVE-2026-76057
4.3 MEDIUM

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions …

Aug 22, 2026
CVE-2026-75027
5.3 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin …

Aug 22, 2026
CVE-2026-19883
8.8 HIGH

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing …

Aug 22, 2026
CVE-2026-77781
7.5 HIGH

Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on …

Aug 22, 2026
CVE-2026-9052

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026
CVE-2026-76069

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.