CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6230
7.5 HIGH

The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all versions up to and including 1.0.3 due …

Jul 8, 2026
CVE-2026-3688
8.1 HIGH

The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Jul 8, 2026
CVE-2026-56003
8.5 HIGH

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could …

Jul 8, 2026
CVE-2026-56002
8.5 HIGH

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client to execute code within …

Jul 8, 2026
CVE-2026-57260
7.8 HIGH

The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as …

Jul 8, 2026
CVE-2026-57256
7.8 HIGH

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the …

Jul 8, 2026
CVE-2026-57254
7.8 HIGH

There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper …

Jul 8, 2026
CVE-2026-57252
7.8 HIGH

When the application opens a PDF file, during the process of JavaScript deleting pages and removing attachment annotations, it will cause the attachment panel to …

Jul 8, 2026
CVE-2026-57251
7.8 HIGH

The application opens a PDF, but the cloud-like appearance of the construction process lacks proper setting of an upper limit and consistency checks. Out-of-bounds access …

Jul 8, 2026
CVE-2026-57250
7.8 HIGH

When the application opens a PDF and JavaScript resets the form fields, the script re-enters the interface. The underlying native object is damaged, but the …

Jul 8, 2026
CVE-2026-57249
7.8 HIGH

After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form event by additional action. During the …

Jul 8, 2026
CVE-2026-57248
7.8 HIGH

When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a …

Jul 8, 2026
CVE-2026-57247
7.8 HIGH

The application re-enters the document structure via field processing and deletes the current page, and then continues using the field objects obtained before deletion, triggering …

Jul 8, 2026
CVE-2026-57246
7.8 HIGH

When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation …

Jul 8, 2026
CVE-2026-57245
7.8 HIGH

When the application opens a PDF, traverses and builds the annotation elements related to hyperlinks, it fails to validate the abnormal annotation relationships and field …

Jul 8, 2026
CVE-2026-57244
7.8 HIGH

After JavaScript resetting the form, the synchronization process lacks re-entry protection and object lifecycle verification, resulting in the failure of the control pointer during the …

Jul 8, 2026
CVE-2026-57242
7.8 HIGH

The application opens the PDF, and JavaScript modifies the form. However, the related objects on the page lack complete lifecycle management and null value validation; …

Jul 8, 2026
CVE-2026-57240
7.8 HIGH

When the application opens a PDF file and JavaScript deletes the PDF fields, the subsequent logic still uses the old field pointers, resulting in invalid …

Jul 8, 2026
CVE-2026-57239
8.2 HIGH

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

Jul 8, 2026
CVE-2026-57238
7.8 HIGH

After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to …

Jul 8, 2026
CVE-2026-57237
7.8 HIGH

When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the …

Jul 8, 2026
CVE-2026-56001
8.5 HIGH

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the …

Jul 8, 2026
CVE-2026-56000
7.8 HIGH

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a …

Jul 8, 2026
CVE-2026-55999
8.5 HIGH

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a …

Jul 8, 2026
CVE-2026-13129
7.8 HIGH

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form …

Jul 8, 2026
CVE-2026-13128
7.8 HIGH

Embedding JavaScript within a PDF file will cause the page to be deleted. Subsequent scripts will continue to access the relevant properties of the document …

Jul 8, 2026
CVE-2026-13127
7.8 HIGH

The application opens the PDF file. JavaScript then rewrites the document to modify the page structure, resulting in the invalidation of the page objects. However, …

Jul 8, 2026
CVE-2026-13126
7.8 HIGH

The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up …

Jul 8, 2026
CVE-2026-12378
8.1 HIGH

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin through 1.1.28 does not validate data before passing it to a PHP deserialization function, allowing …

Jul 8, 2026
CVE-2026-9700
7.5 HIGH

The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to …

Jul 8, 2026
CVE-2026-57895
7.8 HIGH

Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folder, which results in …

Jul 8, 2026
CVE-2026-56437
7.8 HIGH

Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the …

Jul 8, 2026
CVE-2026-14495
8.8 HIGH

The DoLogin Security plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Randomness in all versions up to, and including, 4.3. The vulnerability exists …

Jul 8, 2026
CVE-2026-14489
8.8 HIGH

The WHMCS Bridge plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the connect() function in all versions …

Jul 8, 2026
CVE-2026-9842
7.5 HIGH

The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due …

Jul 8, 2026
CVE-2026-14482
8.8 HIGH

The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists due to a missing …

Jul 8, 2026
CVE-2026-14244
7.5 HIGH

The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.1.24 via the 'url' parameter …

Jul 8, 2026
CVE-2026-14158
8.8 HIGH

The Widget Logic Visual plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.52 via the widget_logic_visual_check_visibility function. …

Jul 8, 2026
CVE-2026-60002
7.7 HIGH

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on …

Jul 8, 2026
CVE-2026-55436
7.4 HIGH

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge …

Jul 8, 2026
CVE-2026-55431
7.7 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs …

Jul 8, 2026
CVE-2026-55429
8.7 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on …

Jul 8, 2026
CVE-2026-55428
8.2 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's …

Jul 8, 2026
CVE-2026-55427
8.3 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, …

Jul 8, 2026
CVE-2026-59704
7.1 HIGH

Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can …

Jul 7, 2026
CVE-2026-55077
7.2 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` …

Jul 7, 2026
CVE-2026-55076
7.4 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a …

Jul 7, 2026
CVE-2026-51937
7.5 HIGH

An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component

Jul 7, 2026
CVE-2026-14895
7.5 HIGH

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. …

Jul 7, 2026
CVE-2026-14380
8.8 HIGH

DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, …

Jul 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.