CVE Database

45033+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89253
8.7 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates …

Sep 11, 2026
CVE-2026-89250
7.5 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers …

Sep 11, 2026
CVE-2026-89249
8.7 HIGH

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage …

Sep 11, 2026
CVE-2026-89243
8.1 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inject …

Sep 11, 2026
CVE-2026-89242
7.2 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF …

Sep 11, 2026
CVE-2026-87776
7.5 HIGH

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being …

Sep 11, 2026
CVE-2026-89147
7.5 HIGH

Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted …

Sep 11, 2026
CVE-2026-89146
7.5 HIGH

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send …

Sep 11, 2026
CVE-2026-17037
7.2 HIGH

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘comment’ parameter in all …

Sep 11, 2026
CVE-2026-80469
8.3 HIGH

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the …

Sep 11, 2026
CVE-2026-89178
8.8 HIGH

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher …

Sep 11, 2026
CVE-2026-89177
8.8 HIGH

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated …

Sep 11, 2026
CVE-2026-89176
8.8 HIGH

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student …

Sep 11, 2026
CVE-2026-89174
7.5 HIGH

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through …

Sep 11, 2026
CVE-2026-87908
7.5 HIGH

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound …

Sep 11, 2026
CVE-2026-85677
8.8 HIGH

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant …

Sep 11, 2026
CVE-2026-74925
7.2 HIGH

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant …

Sep 11, 2026
CVE-2026-73785
7.5 HIGH

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

Sep 11, 2026
CVE-2026-73784
8.8 HIGH

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

Sep 11, 2026
CVE-2026-89060
7.7 HIGH

A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside …

Sep 11, 2026
CVE-2026-89161
7.4 HIGH

In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

Sep 11, 2026
CVE-2026-81825
7.2 HIGH

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all …

Sep 11, 2026
CVE-2026-81754
7.2 HIGH

The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in …

Sep 11, 2026
CVE-2026-19991
8.1 HIGH

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin …

Sep 11, 2026
CVE-2026-18579
7.2 HIGH

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, …

Sep 11, 2026
CVE-2026-18561
7.5 HIGH

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This …

Sep 11, 2026
CVE-2026-15462
7.5 HIGH

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions …

Sep 11, 2026
CVE-2026-78134
7.1 HIGH

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Sep 11, 2026
CVE-2026-78133
7.5 HIGH

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

Sep 11, 2026
CVE-2026-78132
7.5 HIGH

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

Sep 11, 2026
CVE-2026-78130
7.5 HIGH

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

Sep 11, 2026
CVE-2026-77807
7.5 HIGH

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up …

Sep 11, 2026
CVE-2026-87958
8.1 HIGH

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can …

Sep 10, 2026
CVE-2026-86093
7.5 HIGH

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to …

Sep 10, 2026
CVE-2026-84889
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a …

Sep 10, 2026
CVE-2026-82099
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements …

Sep 10, 2026
CVE-2026-82098
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements …

Sep 10, 2026
CVE-2026-82097
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) …

Sep 10, 2026
CVE-2026-82095
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements …

Sep 10, 2026
CVE-2026-82092
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

Sep 10, 2026
CVE-2026-81941
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of …

Sep 10, 2026
CVE-2026-81940
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow …

Sep 10, 2026
CVE-2026-81554
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

Sep 10, 2026
CVE-2026-81551
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due …

Sep 10, 2026
CVE-2026-81550
8.8 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements …

Sep 10, 2026
CVE-2026-81540
8.5 HIGH

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a …

Sep 10, 2026
CVE-2026-81268
8.1 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of …

Sep 10, 2026
CVE-2026-81265
7.5 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5.

Sep 10, 2026
CVE-2026-81213
8.6 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied …

Sep 10, 2026
CVE-2026-81211
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.