CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-5051
4.4 MEDIUM

HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin directory protections when the legacy file audit path …

Jul 1, 2026
CVE-2026-57737
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Phlox theme allows DOM-Based XSS. This …

Jul 1, 2026
CVE-2026-57722
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored XSS. This issue affects Enable Media Replace: …

Jul 1, 2026
CVE-2026-51946
6.5 MEDIUM

SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type …

Jul 1, 2026
CVE-2026-49090
6.5 MEDIUM

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted …

Jul 1, 2026
CVE-2026-57721
5.3 MEDIUM

Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline: from n/a through 2.6.7.6.

Jul 1, 2026
CVE-2026-57720
4.3 MEDIUM

Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ThumbPress: from n/a through 6.3.2.

Jul 1, 2026
CVE-2026-56152
5.3 MEDIUM

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a …

Jul 1, 2026
CVE-2026-56151
6.5 MEDIUM

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can submit a specially …

Jul 1, 2026
CVE-2026-56150
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker can …

Jul 1, 2026
CVE-2026-56149
4.9 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated …

Jul 1, 2026
CVE-2026-56148
6.5 MEDIUM

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted query …

Jul 1, 2026
CVE-2026-49088
4.4 MEDIUM

Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance monitoring (APM) instrumentation is enabled, …

Jul 1, 2026
CVE-2026-49087
6.5 MEDIUM

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can …

Jul 1, 2026
CVE-2026-34098
4.6 MEDIUM

Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action attributes in media.php (lines 119, 129). An …

Jul 1, 2026
CVE-2026-34097
4.6 MEDIUM

Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attributes in text_file.php (lines 94, 101, 323, 403, …

Jul 1, 2026
CVE-2026-34096
4.6 MEDIUM

Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribute in designer.php (line 57). An authenticated attacker …

Jul 1, 2026
CVE-2026-27409
5.3 MEDIUM

Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13.

Jul 1, 2026
CVE-2026-13211
4.3 MEDIUM

The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or …

Jul 1, 2026
CVE-2026-12480
5.5 MEDIUM

Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides …

Jul 1, 2026
CVE-2026-8480
4.3 MEDIUM

A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client …

Jul 1, 2026
CVE-2026-24266
5.9 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead …

Jul 1, 2026
CVE-2026-6686
4.6 MEDIUM

FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use …

Jul 1, 2026
CVE-2026-6685
6.1 MEDIUM

FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read() / f_write() (fp->sect - sect < cc) during interleaved read/write on …

Jul 1, 2026
CVE-2026-6684
4.6 MEDIUM

FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field …

Jul 1, 2026
CVE-2026-6683
4.6 MEDIUM

FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. …

Jul 1, 2026
CVE-2026-6283
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from …

Jul 1, 2026
CVE-2026-5220
6.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from …

Jul 1, 2026
CVE-2026-5142
6.5 MEDIUM

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from …

Jul 1, 2026
CVE-2026-5138
4.3 MEDIUM

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope …

Jul 1, 2026
CVE-2026-5135
6.5 MEDIUM

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override …

Jul 1, 2026
CVE-2026-14330
5.5 MEDIUM

Multiple unbounded alloca() calls in the PulseAudio protocol server.

Jul 1, 2026
CVE-2026-14324
6.5 MEDIUM

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

Jul 1, 2026
CVE-2026-53909
6.5 MEDIUM

MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypassed. An authorized, low-privileged …

Jul 1, 2026
CVE-2026-53908
4.3 MEDIUM

MCO is vulnerable to User Enumeration through authentication-related functionalities. The application returns distinguishable responses for valid and invalid users during username reminder and password reset …

Jul 1, 2026
CVE-2026-53907
5.4 MEDIUM

MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the application logo can …

Jul 1, 2026
CVE-2026-53902
6.5 MEDIUM

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated user can modify their group membership without proper authorization checks, allowing privilege …

Jul 1, 2026
CVE-2026-13323
4.1 MEDIUM

In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. …

Jul 1, 2026
CVE-2026-14258
6.5 MEDIUM

A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specially crafted IPv6 Router Advertisement containing a zero-length Neighbor Discovery option can …

Jul 1, 2026
CVE-2026-10095
6.4 MEDIUM

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and including, …

Jul 1, 2026
CVE-2026-27435
5.3 MEDIUM

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Woffice: from n/a before 5.4.33.

Jul 1, 2026
CVE-2026-13454
6.5 MEDIUM

The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 2.4.5 …

Jul 1, 2026
CVE-2026-12754
6.1 MEDIUM

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all versions up to, …

Jul 1, 2026
CVE-2026-56016
5.9 MEDIUM

CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the session id from a MD5 digest of …

Jul 1, 2026
CVE-2026-13733
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due …

Jul 1, 2026
CVE-2026-12732
6.4 MEDIUM

The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, and including, 4.4.0. This is …

Jul 1, 2026
CVE-2026-12435
4.3 MEDIUM

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.111. …

Jul 1, 2026
CVE-2026-12408
4.3 MEDIUM

The Slim SEO – A Fast & Automated SEO Plugin For WordPress plugin for WordPress is vulnerable to Unauthorized Private Content Disclosure in all versions …

Jul 1, 2026
CVE-2026-10540
5.6 MEDIUM

The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an …

Jul 1, 2026
CVE-2026-10096
4.3 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.9 via the 'page_id' parameter …

Jul 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.