CVE Database

52018+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-4298
4.3 MEDIUM

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is …

Jul 9, 2026
CVE-2026-12428
6.5 MEDIUM

The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function …

Jul 9, 2026
CVE-2026-5793
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: …

Jul 9, 2026
CVE-2026-56460
6.5 MEDIUM

HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks …

Jul 9, 2026
CVE-2026-56459
6.2 MEDIUM

HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read …

Jul 9, 2026
CVE-2026-56458
5.4 MEDIUM

HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain …

Jul 9, 2026
CVE-2026-1365
6.5 MEDIUM

Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The …

Jul 9, 2026
CVE-2026-12433
4.3 MEDIUM

The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, …

Jul 9, 2026
CVE-2026-8996
6.5 MEDIUM

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 …

Jul 9, 2026
CVE-2026-7558
5.3 MEDIUM

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including …

Jul 9, 2026
CVE-2026-6910
6.4 MEDIUM

The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions …

Jul 9, 2026
CVE-2026-4653
6.4 MEDIUM

The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including …

Jul 9, 2026
CVE-2026-31983
5.3 MEDIUM

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint …

Jul 9, 2026
CVE-2026-31981
5.9 MEDIUM

A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An …

Jul 9, 2026
CVE-2026-14343
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, …

Jul 9, 2026
CVE-2026-14342
4.9 MEDIUM

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to time-based SQL Injection via the 'contact_ids' parameter …

Jul 9, 2026
CVE-2026-13771
6.4 MEDIUM

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'color' Shortcode Attribute in all versions up to, and including, …

Jul 9, 2026
CVE-2026-13450
5.3 MEDIUM

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in …

Jul 9, 2026
CVE-2026-13334
6.1 MEDIUM

The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'stag' parameter in all versions up to, and including, 2.3.4 …

Jul 9, 2026
CVE-2026-13253
6.4 MEDIUM

The Ultimate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'moreResultsText' block attribute of the ultimate-post/advanced-search block in versions up to …

Jul 9, 2026
CVE-2026-13080
6.6 MEDIUM

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions …

Jul 9, 2026
CVE-2026-13011
6.5 MEDIUM

The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulnerable to generic SQL Injection via the …

Jul 9, 2026
CVE-2026-12418
5.3 MEDIUM

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in …

Jul 9, 2026
CVE-2026-12406
5.3 MEDIUM

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to authorization bypass in all versions …

Jul 9, 2026
CVE-2026-12170
6.4 MEDIUM

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' …

Jul 9, 2026
CVE-2026-11359
4.3 MEDIUM

The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up …

Jul 9, 2026
CVE-2026-12517
5.3 MEDIUM

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-info endpoint before fetching it, …

Jul 9, 2026
CVE-2026-12516
5.3 MEDIUM

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media-proxying endpoint, allowing anonymous users …

Jul 9, 2026
CVE-2026-12270
6.5 MEDIUM

The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assistant: the capability check …

Jul 9, 2026
CVE-2026-11875
5.3 MEDIUM

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it …

Jul 9, 2026
CVE-2026-11869
5.3 MEDIUM

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject access request …

Jul 9, 2026
CVE-2026-15138
6.3 MEDIUM

A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_text_editor/text_editor.py. Such manipulation of …

Jul 9, 2026
CVE-2026-54779
5.9 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay …

Jul 8, 2026
CVE-2026-54778
6.2 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer …

Jul 8, 2026
CVE-2026-54776
4.4 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service hosted …

Jul 8, 2026
CVE-2026-54775
6.5 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a CoreWCF service listening …

Jul 8, 2026
CVE-2026-54773
5.9 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF WS-Security signature verification …

Jul 8, 2026
CVE-2026-15131
4.3 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security …

Jul 8, 2026
CVE-2026-15130
4.3 MEDIUM

Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium …

Jul 8, 2026
CVE-2026-15128
6.1 MEDIUM

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Jul 8, 2026
CVE-2026-15127
6.1 MEDIUM

Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML …

Jul 8, 2026
CVE-2026-15124
4.3 MEDIUM

Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. …

Jul 8, 2026
CVE-2026-15109
6.5 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 8, 2026
CVE-2026-15108
4.3 MEDIUM

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform …

Jul 8, 2026
CVE-2026-15105
6.3 MEDIUM

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request …

Jul 8, 2026
CVE-2026-55877
6.1 MEDIUM

Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and …

Jul 8, 2026
CVE-2026-54777
6.5 MEDIUM

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF NetNamedPipe transport accepts …

Jul 8, 2026
CVE-2026-48492
6.5 MEDIUM

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorization check. Any user who can …

Jul 8, 2026
CVE-2026-39179
6.3 MEDIUM

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.

Jul 8, 2026
CVE-2026-39178
6.3 MEDIUM

A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.

Jul 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.