CVE Database

133011+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9593
6.7 MEDIUM

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing …

Aug 3, 2026
CVE-2026-4793
7.3 HIGH

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

Aug 3, 2026
CVE-2026-18589
9.8 CRITICAL

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in …

Aug 3, 2026
CVE-2026-18588
9.8 CRITICAL

A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads …

Aug 3, 2026
CVE-2026-18587
7.5 HIGH

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of …

Aug 3, 2026
CVE-2026-16572
8.6 HIGH

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing …

Aug 3, 2026
CVE-2026-16565
4.3 MEDIUM

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users …

Aug 3, 2026
CVE-2026-16564
4.3 MEDIUM

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status …

Aug 3, 2026
CVE-2026-16563
6.5 MEDIUM

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, …

Aug 3, 2026
CVE-2026-16539
8.1 HIGH

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating …

Aug 3, 2026
CVE-2026-16534
9.1 CRITICAL

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a …

Aug 3, 2026
CVE-2026-16532
9.1 CRITICAL

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated …

Aug 3, 2026
CVE-2026-16300
9.8 CRITICAL

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including …

Aug 3, 2026
CVE-2026-16297
4.1 MEDIUM

The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP …

Aug 3, 2026
CVE-2026-16289
4.3 MEDIUM

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a …

Aug 3, 2026
CVE-2026-16276
2.7 LOW

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users …

Aug 3, 2026
CVE-2026-16274
2.7 LOW

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing …

Aug 3, 2026
CVE-2026-16250
9.8 CRITICAL

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users …

Aug 3, 2026
CVE-2026-16060
9.8 CRITICAL

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable …

Aug 3, 2026
CVE-2026-16057
6.5 MEDIUM

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by …

Aug 3, 2026
CVE-2026-15931
6.1 MEDIUM

The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when …

Aug 3, 2026
CVE-2026-15930
9.4 CRITICAL

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID …

Aug 3, 2026
CVE-2026-15383
6.1 MEDIUM

The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST …

Aug 3, 2026
CVE-2026-15260
4.3 MEDIUM

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users …

Aug 3, 2026
CVE-2026-15254
6.5 MEDIUM

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails …

Aug 3, 2026
CVE-2026-15231
2.7 LOW

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing …

Aug 3, 2026
CVE-2026-14557
9.1 CRITICAL

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-verification flow, allowing unauthenticated …

Aug 3, 2026
CVE-2026-13340
6.1 MEDIUM

The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and …

Aug 3, 2026
CVE-2026-12965
9.1 CRITICAL

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, …

Aug 3, 2026
CVE-2026-12872
9.8 CRITICAL

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, …

Aug 3, 2026
CVE-2025-15673
4.9 MEDIUM

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a …

Aug 3, 2026
CVE-2025-15672
8.1 HIGH

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject …

Aug 3, 2026
CVE-2026-6695
5.5 MEDIUM

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro …

Aug 3, 2026
CVE-2026-6694
5.5 MEDIUM

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing …

Aug 3, 2026
CVE-2026-18585
4.3 MEDIUM

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is …

Aug 3, 2026
CVE-2026-18584
5.4 MEDIUM

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the …

Aug 3, 2026
CVE-2026-18583
5.3 MEDIUM

A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS …

Aug 3, 2026
CVE-2026-14682

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Castle for Java …

Aug 3, 2026
CVE-2026-13586

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java LTS before …

Aug 3, 2026
CVE-2026-13506

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS before 2.73.12, …

Aug 3, 2026
CVE-2026-12860

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle for …

Aug 3, 2026
CVE-2026-12852

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

Aug 3, 2026
CVE-2026-12817

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java LTS …

Aug 3, 2026
CVE-2026-12816

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Java LTS before …

Aug 3, 2026
CVE-2026-12803

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects Bouncy …

Aug 3, 2026
CVE-2026-12802

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Java LTS before …

Aug 3, 2026
CVE-2026-58063

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for Java …

Aug 3, 2026
CVE-2026-58062

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java …

Aug 3, 2026
CVE-2026-58061

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for Java …

Aug 3, 2026
CVE-2026-58060

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castle for Java …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.