CVE Database

45033+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78491
8.2 HIGH

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated …

Sep 9, 2026
CVE-2026-14989
7.2 HIGH

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpl_user_preference' parameter in …

Sep 9, 2026
CVE-2026-14359
8.8 HIGH

The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the …

Sep 9, 2026
CVE-2026-80123
7.3 HIGH

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An …

Sep 9, 2026
CVE-2026-79636
7.0 HIGH

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host …

Sep 9, 2026
CVE-2026-75927
7.2 HIGH

The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up …

Sep 9, 2026
CVE-2026-84068
8.6 HIGH

The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers …

Sep 9, 2026
CVE-2026-83593
7.2 HIGH

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter …

Sep 9, 2026
CVE-2026-76009
8.1 HIGH

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` …

Sep 9, 2026
CVE-2026-16960
7.5 HIGH

The Loops & Logic WordPress plugin before 4.3.0 does not restrict its public template-data action to the data a visitor is permitted to see, allowing …

Sep 9, 2026
CVE-2026-14962
8.6 HIGH

The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, …

Sep 9, 2026
CVE-2026-87734
7.5 HIGH

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

Sep 9, 2026
CVE-2026-21100
7.1 HIGH

Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.

Sep 9, 2026
CVE-2026-21094
8.8 HIGH

Improper input validation in wpa_supplicant prior to SMR Sep-2026 Release 1 allows adjacent attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21091
7.8 HIGH

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21090
7.8 HIGH

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21089
7.8 HIGH

Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21088
7.8 HIGH

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Sep 9, 2026
CVE-2026-21087
7.8 HIGH

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

Sep 9, 2026
CVE-2026-84293
7.2 HIGH

The Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeated Multi-Input Sub-Field Values in all versions up to, …

Sep 9, 2026
CVE-2026-6485
8.2 HIGH

UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.

Sep 9, 2026
CVE-2026-49315
7.1 HIGH

DoS vulnerability in the input device module. Impact: Successful exploitation of this vulnerability may affect availability.

Sep 9, 2026
CVE-2026-49314
7.3 HIGH

OOB write vulnerability in the rendering and composition module. Impact: Successful exploitation of this vulnerability may affect availability.

Sep 9, 2026
CVE-2026-49310
8.6 HIGH

Permission control vulnerability in the event notification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 9, 2026
CVE-2026-17553
7.2 HIGH

The WP EasyCart plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.9.3. This is due to the ec_ajax_save_page_default_options() AJAX …

Sep 9, 2026
CVE-2026-12855
8.2 HIGH

Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.

Sep 9, 2026
CVE-2026-87088
7.0 HIGH

Tanium addressed an unauthorized code execution vulnerability in Enforce.

Sep 9, 2026
CVE-2026-87084
7.7 HIGH

Tanium addressed a server-side request forgery vulnerability in Enforce.

Sep 9, 2026
CVE-2026-87075
8.1 HIGH

Tanium addressed an improper access controls vulnerability in Comply.

Sep 9, 2026
CVE-2026-87072
7.1 HIGH

Tanium addressed an improper access controls vulnerability in Comply.

Sep 9, 2026
CVE-2026-87036
8.1 HIGH

Tanium addressed an improper access controls vulnerability in Comply.

Sep 9, 2026
CVE-2026-87034
8.3 HIGH

Tanium addressed a SQL injection vulnerability in Comply.

Sep 9, 2026
CVE-2026-87030
8.5 HIGH

Tanium addressed a path traversal vulnerability in Comply.

Sep 9, 2026
CVE-2026-87023
8.5 HIGH

Tanium addressed a path traversal vulnerability in Comply.

Sep 9, 2026
CVE-2026-87021
7.2 HIGH

Tanium addressed an unauthorized code execution vulnerability in Comply.

Sep 9, 2026
CVE-2026-76801
8.8 HIGH

The FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment plugin for WordPress is vulnerable to Remote Code Execution in all …

Sep 9, 2026
CVE-2026-15667
7.5 HIGH

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

Sep 9, 2026
CVE-2026-15406
7.5 HIGH

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

Sep 9, 2026
CVE-2026-13359
7.2 HIGH

The Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cntctfrm_contact_dropdown Parameter …

Sep 9, 2026
CVE-2026-87648
8.3 HIGH

Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to …

Sep 9, 2026
CVE-2026-87644
8.3 HIGH

Incorrect authorization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 9, 2026
CVE-2026-87639
8.3 HIGH

Use after free in WebPackaging in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary …

Sep 9, 2026
CVE-2026-87636
8.8 HIGH

Type confusion in XML in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted …

Sep 9, 2026
CVE-2026-87633
8.6 HIGH

Use after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UI Interaction. …

Sep 9, 2026
CVE-2026-87628
8.3 HIGH

Use after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted …

Sep 9, 2026
CVE-2026-87625
8.8 HIGH

Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Sep 9, 2026
CVE-2026-87618
8.3 HIGH

Incorrect reference resolution in Storage in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to …

Sep 9, 2026
CVE-2026-87617
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox …

Sep 9, 2026
CVE-2026-87616
8.3 HIGH

Improper initialization in Views in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 9, 2026
CVE-2026-87612
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.