CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13357
4.9 MEDIUM

The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due …

Jul 2, 2026
CVE-2026-11965
6.5 MEDIUM

The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering …

Jul 2, 2026
CVE-2026-11600
4.3 MEDIUM

The Envo's Templates & Widgets for Elementor and WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check …

Jul 2, 2026
CVE-2026-11592
4.3 MEDIUM

The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all …

Jul 2, 2026
CVE-2026-10089
6.4 MEDIUM

The Insert Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post custom field keys (meta key names) in all versions up to, …

Jul 2, 2026
CVE-2026-10077
6.8 MEDIUM

The yootheme WordPress theme before 5.0.35 does not prevent its bundled front-end framework from treating certain HTML attributes, which are permitted by wp_kses_post(), as markup, …

Jul 2, 2026
CVE-2026-14440
6.8 MEDIUM

Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automatically manages the CAA RRset for the customer's zone. This …

Jul 1, 2026
CVE-2026-14421
6.5 MEDIUM

Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via …

Jul 1, 2026
CVE-2026-14418
4.3 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jul 1, 2026
CVE-2026-14414
5.3 MEDIUM

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain …

Jul 1, 2026
CVE-2026-14410
4.3 MEDIUM

Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via …

Jul 1, 2026
CVE-2026-14408
6.5 MEDIUM

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 1, 2026
CVE-2026-14406
5.9 MEDIUM

Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to …

Jul 1, 2026
CVE-2026-14404
6.5 MEDIUM

Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security …

Jul 1, 2026
CVE-2026-14402
6.5 MEDIUM

Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via …

Jul 1, 2026
CVE-2026-14399
6.5 MEDIUM

Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

Jul 1, 2026
CVE-2026-14396
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

Jul 1, 2026
CVE-2026-14391
5.3 MEDIUM

Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially …

Jul 1, 2026
CVE-2026-14388
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via …

Jul 1, 2026
CVE-2026-14386
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via …

Jul 1, 2026
CVE-2026-14384
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted …

Jul 1, 2026
CVE-2026-14381
6.5 MEDIUM

Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium …

Jul 1, 2026
CVE-2026-54712
5.3 MEDIUM

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.27.0, the RMI context propagation payload reader limits the number …

Jul 1, 2026
CVE-2026-54704
6.5 MEDIUM

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, the JDBC auto-instrumentation may fail to sanitize passwords in …

Jul 1, 2026
CVE-2026-54262
4.3 MEDIUM

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can …

Jul 1, 2026
CVE-2026-54261
6.5 MEDIUM

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check …

Jul 1, 2026
CVE-2026-54260
4.3 MEDIUM

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger …

Jul 1, 2026
CVE-2026-54259
4.3 MEDIUM

Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen …

Jul 1, 2026
CVE-2026-36911
5.5 MEDIUM

A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted …

Jul 1, 2026
CVE-2026-36910
5.5 MEDIUM

An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted …

Jul 1, 2026
CVE-2026-36909
6.2 MEDIUM

A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a …

Jul 1, 2026
CVE-2026-54786
5.0 MEDIUM

Wasmtime is a runtime for WebAssembly. All versions prior to 24.0.10; versions 25.0.0 through those before 36.0.11; versions 37.0.0 through those before 44.0.3; and versions …

Jul 1, 2026
CVE-2026-54720
5.4 MEDIUM

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in the CMS …

Jul 1, 2026
CVE-2026-14340
5.0 MEDIUM

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a user-to-server token scoped to a GitHub App installation to perform certain write …

Jul 1, 2026
CVE-2026-55688
4.0 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and …

Jul 1, 2026
CVE-2026-54164
6.5 MEDIUM

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's AbstractItemNormalizer does …

Jul 1, 2026
CVE-2026-49858
5.9 MEDIUM

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missing …

Jul 1, 2026
CVE-2026-58451
6.5 MEDIUM

Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to read arbitrary files from the server filesystem by embedding …

Jul 1, 2026
CVE-2026-55628
5.5 MEDIUM

In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security …

Jul 1, 2026
CVE-2026-55597
5.5 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26, an incorrect handling of arguments can cause a …

Jul 1, 2026
CVE-2026-55595
4.7 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when providing invalid arguments to the …

Jul 1, 2026
CVE-2026-55594
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a missing depth check in the …

Jul 1, 2026
CVE-2026-55577
5.9 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, a heap buffer overflow occurs in …

Jul 1, 2026
CVE-2026-55510
5.5 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, when identifying an image with a …

Jul 1, 2026
CVE-2026-53489
6.5 MEDIUM

containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint …

Jul 1, 2026
CVE-2026-53467
5.3 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, the MNG decoder contains a possible …

Jul 1, 2026
CVE-2026-53466
6.5 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-51 and 7.1.2-26, an integer overflow in the XCF …

Jul 1, 2026
CVE-2026-47262
5.5 MEDIUM

containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to …

Jul 1, 2026
CVE-2026-38142
6.5 MEDIUM

An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into …

Jul 1, 2026
CVE-2026-13769
5.5 MEDIUM

Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to restrict …

Jul 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.