CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55950
5.9 MEDIUM

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. …

Jul 2, 2026
CVE-2026-54887
4.8 MEDIUM

Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verification bypass. …

Jul 2, 2026
CVE-2026-54886
4.3 MEDIUM

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently …

Jul 2, 2026
CVE-2026-53422
4.3 MEDIUM

Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the …

Jul 2, 2026
CVE-2026-12166
5.5 MEDIUM

A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests …

Jul 2, 2026
CVE-2026-58653
4.3 MEDIUM

PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues …

Jul 2, 2026
CVE-2026-4772
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from …

Jul 2, 2026
CVE-2026-4770
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects …

Jul 2, 2026
CVE-2026-57764
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

Jul 2, 2026
CVE-2026-57763
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

Jul 2, 2026
CVE-2026-57762
5.9 MEDIUM

Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

Jul 2, 2026
CVE-2026-57760
5.3 MEDIUM

Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

Jul 2, 2026
CVE-2026-57755
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

Jul 2, 2026
CVE-2026-57754
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

Jul 2, 2026
CVE-2026-57753
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

Jul 2, 2026
CVE-2026-57750
5.3 MEDIUM

Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

Jul 2, 2026
CVE-2026-57747
6.5 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

Jul 2, 2026
CVE-2026-57731
6.5 MEDIUM

Contributor Broken Access Control in Flatsome <= 3.20.5 versions.

Jul 2, 2026
CVE-2026-57730
4.3 MEDIUM

Subscriber Broken Access Control in Flatsome <= 3.20.5 versions.

Jul 2, 2026
CVE-2026-57690
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Werkstatt <= 4.7.2 versions.

Jul 2, 2026
CVE-2026-57689
4.3 MEDIUM

Subscriber Broken Access Control in Werkstatt <= 4.7.2 versions.

Jul 2, 2026
CVE-2026-57685
4.3 MEDIUM

Subscriber Broken Access Control in Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8 versions.

Jul 2, 2026
CVE-2026-57684
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in TheFox <= 3.9.70 versions.

Jul 2, 2026
CVE-2026-57681
6.4 MEDIUM

Subscriber Server Side Request Forgery (SSRF) in GeoDirectory <= 2.8.161 versions.

Jul 2, 2026
CVE-2026-57680
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Kirki <= 6.0.11 versions.

Jul 2, 2026
CVE-2026-57669
6.5 MEDIUM

Subscriber Broken Access Control in Advanced Contact form 7 DB <= 2.0.9 versions.

Jul 2, 2026
CVE-2026-57355
6.5 MEDIUM

Subscriber Broken Access Control in Classified Listing <= 5.4.2 versions.

Jul 2, 2026
CVE-2026-57354
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in JetReviews <= 3.0.0.1 versions.

Jul 2, 2026
CVE-2026-57353
6.5 MEDIUM

Subscriber Broken Access Control in Link Whisper Premium <= 2.9.0 versions.

Jul 2, 2026
CVE-2026-57352
4.8 MEDIUM

Unauthenticated Broken Authentication in ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce <= 2.2.0 versions.

Jul 2, 2026
CVE-2026-57347
6.5 MEDIUM

Subscriber Sensitive Data Exposure in Hotel Booking Lite <= 6.0.3 versions.

Jul 2, 2026
CVE-2026-57342
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in ShortPixel Adaptive Images <= 3.11.3 versions.

Jul 2, 2026
CVE-2026-49779
6.5 MEDIUM

Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 versions.

Jul 2, 2026
CVE-2026-27433
6.5 MEDIUM

Unauthenticated Broken Access Control in Motors <= 5.6.80 versions.

Jul 2, 2026
CVE-2025-69132
6.5 MEDIUM

Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.

Jul 2, 2026
CVE-2025-66076
5.3 MEDIUM

Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.

Jul 2, 2026
CVE-2026-9188
5.3 MEDIUM

The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to …

Jul 2, 2026
CVE-2026-9145
6.5 MEDIUM

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up …

Jul 2, 2026
CVE-2026-8482
4.3 MEDIUM

A vulnerability was discovered on StormShield Network Security 4.3.0 to 4.3.41 (included), 4.8.0 to 4.8.15 (included) , 5.0.0 to 5.0.5 (included) There is a possible …

Jul 2, 2026
CVE-2026-14029
6.5 MEDIUM

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'select' parameter in all versions up …

Jul 2, 2026
CVE-2026-13459
5.3 MEDIUM

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is …

Jul 2, 2026
CVE-2026-13252
6.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jul 2, 2026
CVE-2026-12657
5.3 MEDIUM

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Jul 2, 2026
CVE-2026-12472
5.3 MEDIUM

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Jul 2, 2026
CVE-2026-12134
4.3 MEDIUM

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 2, 2026
CVE-2026-12122
5.3 MEDIUM

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Jul 2, 2026
CVE-2026-11896
5.3 MEDIUM

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14 …

Jul 2, 2026
CVE-2026-10104
4.4 MEDIUM

The Product Video Gallery for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom_thumbnail Parameter in all versions up to, and including, …

Jul 2, 2026
CVE-2026-5348
5.3 MEDIUM

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, …

Jul 2, 2026
CVE-2026-13704
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sequoia[introduction][image]' parameter in all versions up …

Jul 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.