CVE Database

52018+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6459
6.4 MEDIUM

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget …

Jul 8, 2026
CVE-2026-5459
5.3 MEDIUM

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in …

Jul 8, 2026
CVE-2026-12002
4.7 MEDIUM

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jul 8, 2026
CVE-2026-6742
6.4 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due …

Jul 8, 2026
CVE-2026-6371
4.8 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc. LimRAD NAC allows Stored XSS. This issue affects LimRAD NAC: …

Jul 8, 2026
CVE-2026-14250
6.3 MEDIUM

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() …

Jul 8, 2026
CVE-2026-12936
4.9 MEDIUM

The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, …

Jul 8, 2026
CVE-2025-14785
6.4 MEDIUM

The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jul 8, 2026
CVE-2026-6280
6.5 MEDIUM

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. …

Jul 8, 2026
CVE-2026-57259
6.5 MEDIUM

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as …

Jul 8, 2026
CVE-2026-57258
6.1 MEDIUM

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to …

Jul 8, 2026
CVE-2026-57257
6.1 MEDIUM

During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the …

Jul 8, 2026
CVE-2026-57255
6.1 MEDIUM

The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; …

Jul 8, 2026
CVE-2026-57253
6.1 MEDIUM

An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, …

Jul 8, 2026
CVE-2026-57243
6.1 MEDIUM

During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application …

Jul 8, 2026
CVE-2026-57241
6.1 MEDIUM

The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; …

Jul 8, 2026
CVE-2026-9731
4.3 MEDIUM

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to …

Jul 8, 2026
CVE-2026-14500
5.3 MEDIUM

The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due …

Jul 8, 2026
CVE-2026-12097
5.3 MEDIUM

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin …

Jul 8, 2026
CVE-2026-12041
4.4 MEDIUM

The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up …

Jul 8, 2026
CVE-2026-11798
6.1 MEDIUM

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter …

Jul 8, 2026
CVE-2026-10570
6.4 MEDIUM

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up …

Jul 8, 2026
CVE-2026-60001
6.5 MEDIUM

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

Jul 8, 2026
CVE-2026-59999
5.9 MEDIUM

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

Jul 8, 2026
CVE-2026-59998
4.8 MEDIUM

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

Jul 8, 2026
CVE-2026-59997
4.2 MEDIUM

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have …

Jul 8, 2026
CVE-2026-59996
4.2 MEDIUM

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

Jul 8, 2026
CVE-2026-59995
4.2 MEDIUM

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Jul 8, 2026
CVE-2026-55438
5.8 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based workspace app proxy allowed the …

Jul 8, 2026
CVE-2026-55437
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without …

Jul 8, 2026
CVE-2026-55433
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route …

Jul 8, 2026
CVE-2026-55432
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a …

Jul 8, 2026
CVE-2026-55430
5.8 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target …

Jul 8, 2026
CVE-2026-55079
4.9 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in …

Jul 8, 2026
CVE-2026-55078
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` …

Jul 7, 2026
CVE-2026-50811
6.5 MEDIUM

An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates

Jul 7, 2026
CVE-2026-50810
5.5 MEDIUM

A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service

Jul 7, 2026
CVE-2026-36163
5.4 MEDIUM

An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's …

Jul 7, 2026
CVE-2026-36162
5.4 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via …

Jul 7, 2026
CVE-2026-58266
6.5 MEDIUM

Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with the Rust backend using an internal localhost API, …

Jul 7, 2026
CVE-2026-55490
6.5 MEDIUM

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker …

Jul 7, 2026
CVE-2026-54601
6.3 MEDIUM

FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticated tenant user to call POST /api/core/dataset/collection/create/reTrainingCollection in …

Jul 7, 2026
CVE-2026-50179
4.2 MEDIUM

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify …

Jul 7, 2026
CVE-2026-45796
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind …

Jul 7, 2026
CVE-2026-58472
5.9 MEDIUM

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker …

Jul 7, 2026
CVE-2026-58471
5.9 MEDIUM

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to …

Jul 7, 2026
CVE-2026-58470
5.3 MEDIUM

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause …

Jul 7, 2026
CVE-2026-55434
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers …

Jul 7, 2026
CVE-2026-53935
6.9 MEDIUM

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to …

Jul 7, 2026
CVE-2026-46700
4.3 MEDIUM

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session …

Jul 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.