CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-56775
5.4 MEDIUM

n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run endpoints that authorize state-changing actions using the workflow:read scope instead …

Jul 8, 2026
CVE-2026-56401
6.5 MEDIUM

Wazuh wazuh-modulesd before 5.0.0-beta3 contains a null pointer dereference vulnerability in inventory_sync FlatBuffer DataValue handling. An enrolled agent can send a verifier-valid DataValue message omitting …

Jul 8, 2026
CVE-2026-56360
4.0 MEDIUM

n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger node. Attackers who know the webhook URL can …

Jul 8, 2026
CVE-2026-56359
5.4 MEDIUM

n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated users can inject malicious JavaScript URLs into OAuth2 credential Authorization …

Jul 8, 2026
CVE-2026-56298
4.3 MEDIUM

Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing …

Jul 8, 2026
CVE-2026-56293
5.4 MEDIUM

Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org when transferring applications between organizations. Attackers can exploit this omission to …

Jul 8, 2026
CVE-2026-56284
5.3 MEDIUM

Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics(org_id), which is callable by the anon role using only …

Jul 8, 2026
CVE-2026-56283
5.4 MEDIUM

Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML content. Attackers can craft payloads …

Jul 8, 2026
CVE-2026-56273
6.5 MEDIUM

Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath parameters from authenticated users. Attackers with …

Jul 8, 2026
CVE-2026-56220
6.5 MEDIUM

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert OTA manifest rows. Attackers with …

Jul 8, 2026
CVE-2026-56217
4.3 MEDIUM

Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers …

Jul 8, 2026
CVE-2026-15035
5.3 MEDIUM

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. …

Jul 8, 2026
CVE-2026-15034
4.3 MEDIUM

A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request …

Jul 8, 2026
CVE-2026-15033
6.3 MEDIUM

A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the file dist/packageUtils.js of the …

Jul 8, 2026
CVE-2026-8315
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored XSS. This issue affects Mediküm Web: …

Jul 8, 2026
CVE-2026-8310
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflected XSS. This issue affects Mediküm Web: …

Jul 8, 2026
CVE-2026-6740
6.4 MEDIUM

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'commentIcon' parameter …

Jul 8, 2026
CVE-2026-6459
6.4 MEDIUM

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Event Calendar widget …

Jul 8, 2026
CVE-2026-5459
5.3 MEDIUM

The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in …

Jul 8, 2026
CVE-2026-12002
4.7 MEDIUM

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, …

Jul 8, 2026
CVE-2026-6742
6.4 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due …

Jul 8, 2026
CVE-2026-6371
4.8 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc. LimRAD NAC allows Stored XSS. This issue affects LimRAD NAC: …

Jul 8, 2026
CVE-2026-14250
6.3 MEDIUM

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() …

Jul 8, 2026
CVE-2026-12936
4.9 MEDIUM

The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, …

Jul 8, 2026
CVE-2025-14785
6.4 MEDIUM

The Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jul 8, 2026
CVE-2026-6280
6.5 MEDIUM

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. …

Jul 8, 2026
CVE-2026-57259
6.5 MEDIUM

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as …

Jul 8, 2026
CVE-2026-57258
6.1 MEDIUM

The PRC file header parsing logic trusts the constructed file structure description information, assumes that the underlying array contains elements and reads them, leading to …

Jul 8, 2026
CVE-2026-57257
6.1 MEDIUM

During the PRC parsing stage, there is a lack of boundary verification for the PRC entity index, which leads to an out-of-bounds read of the …

Jul 8, 2026
CVE-2026-57255
6.1 MEDIUM

The application opens a PDF containing an abnormal color space whose attributes reference a valid but semantically malformed function. The function's output is not validated; …

Jul 8, 2026
CVE-2026-57253
6.1 MEDIUM

An abnormal image object causes the renderer to enter the wrong processing branch. When converting the scan lines, an invalid image buffer pointer is used, …

Jul 8, 2026
CVE-2026-57243
6.1 MEDIUM

During the process of page opening and form formatting, a JavaScript reentrancy results in an inconsistent document status. Subsequently, with outdated page information, the application …

Jul 8, 2026
CVE-2026-57241
6.1 MEDIUM

The application opens the PDF, and JavaScript performs operations on the page and the document, causing the page-related objects within the application to lose synchronization; …

Jul 8, 2026
CVE-2026-9731
4.3 MEDIUM

The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to …

Jul 8, 2026
CVE-2026-14500
5.3 MEDIUM

The Bulk Order Update for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.6. This is due …

Jul 8, 2026
CVE-2026-12097
5.3 MEDIUM

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin …

Jul 8, 2026
CVE-2026-12041
4.4 MEDIUM

The Chatra Live Chat + ChatBot + Cart Saver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up …

Jul 8, 2026
CVE-2026-11798
6.1 MEDIUM

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter …

Jul 8, 2026
CVE-2026-10570
6.4 MEDIUM

The Sympl Repeater for ACF and Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ACF repeater field values in all versions up …

Jul 8, 2026
CVE-2026-60001
6.5 MEDIUM

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

Jul 8, 2026
CVE-2026-59999
5.9 MEDIUM

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

Jul 8, 2026
CVE-2026-59998
4.8 MEDIUM

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

Jul 8, 2026
CVE-2026-59997
4.2 MEDIUM

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have …

Jul 8, 2026
CVE-2026-59996
4.2 MEDIUM

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

Jul 8, 2026
CVE-2026-59995
4.2 MEDIUM

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Jul 8, 2026
CVE-2026-55438
5.8 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based workspace app proxy allowed the …

Jul 8, 2026
CVE-2026-55437
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without …

Jul 8, 2026
CVE-2026-55433
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route …

Jul 8, 2026
CVE-2026-55432
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a …

Jul 8, 2026
CVE-2026-55430
5.8 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target …

Jul 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.