CVE Database

134505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-15574
7.5 HIGH

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat payloads, which may contain personally …

Jul 13, 2026
CVE-2026-15547
6.3 MEDIUM

A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation …

Jul 13, 2026
CVE-2026-15546
6.3 MEDIUM

A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing …

Jul 13, 2026
CVE-2026-15545
8.8 HIGH

A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component …

Jul 13, 2026
CVE-2026-14453
9.6 CRITICAL

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without …

Jul 13, 2026
CVE-2026-10106
6.5 MEDIUM

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel …

Jul 13, 2026
CVE-2026-10103
4.3 MEDIUM

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows …

Jul 13, 2026
CVE-2026-10085
5.4 MEDIUM

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support …

Jul 13, 2026
CVE-2026-57830
9.1 CRITICAL

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Jul 13, 2026
CVE-2026-57829
6.1 MEDIUM

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

Jul 13, 2026
CVE-2026-4769
9.8 CRITICAL

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented …

Jul 13, 2026
CVE-2026-15544
8.8 HIGH

A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation …

Jul 13, 2026
CVE-2026-15543
8.8 HIGH

A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in …

Jul 13, 2026
CVE-2026-15542
7.3 HIGH

A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection …

Jul 13, 2026
CVE-2026-15541
7.3 HIGH

A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component …

Jul 13, 2026
CVE-2026-15540
4.3 MEDIUM

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component …

Jul 13, 2026
CVE-2026-14165
7.5 HIGH

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users …

Jul 13, 2026
CVE-2026-15539
4.7 MEDIUM

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component …

Jul 13, 2026
CVE-2026-15538
6.3 MEDIUM

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the …

Jul 13, 2026
CVE-2026-15537
7.3 HIGH

A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of …

Jul 13, 2026
CVE-2026-15536
6.3 MEDIUM

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid …

Jul 13, 2026
CVE-2026-12582
8.6 HIGH

The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated …

Jul 13, 2026
CVE-2026-12397
4.3 MEDIUM

The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users …

Jul 13, 2026
CVE-2026-12396
5.4 MEDIUM

The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a …

Jul 13, 2026
CVE-2026-12275
7.1 HIGH

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it …

Jul 13, 2026
CVE-2026-12274
6.5 MEDIUM

The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in …

Jul 13, 2026
CVE-2026-12273
4.3 MEDIUM

The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and …

Jul 13, 2026
CVE-2026-12271
5.4 MEDIUM

The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level …

Jul 13, 2026
CVE-2026-12081
5.0 MEDIUM

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field …

Jul 13, 2026
CVE-2026-11964
9.1 CRITICAL

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated …

Jul 13, 2026
CVE-2026-11963
8.1 HIGH

The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify …

Jul 13, 2026
CVE-2026-10551
6.1 MEDIUM

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML …

Jul 13, 2026
CVE-2026-15535
6.3 MEDIUM

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component …

Jul 13, 2026
CVE-2026-15533
4.7 MEDIUM

A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a …

Jul 13, 2026
CVE-2026-15532
2.4 LOW

A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation …

Jul 13, 2026
CVE-2026-15531
5.3 MEDIUM

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the …

Jul 13, 2026
CVE-2026-15530
5.3 MEDIUM

A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component …

Jul 13, 2026
CVE-2026-9492
7.8 HIGH

The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can …

Jul 13, 2026
CVE-2026-7162
7.8 HIGH

Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.

Jul 13, 2026
CVE-2026-15553
5.3 MEDIUM

Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for …

Jul 13, 2026
CVE-2026-15552
6.1 MEDIUM

Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers …

Jul 13, 2026
CVE-2026-15529
6.3 MEDIUM

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results …

Jul 13, 2026
CVE-2026-15528
3.3 LOW

A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the …

Jul 13, 2026
CVE-2026-15527
5.3 MEDIUM

A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the component scan_project_icons/sync_icon. Such manipulation of the argument …

Jul 13, 2026
CVE-2026-15526
3.3 LOW

A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file src/tools/v4/scan-project-deps.ts of the component scan_project_deps. Executing a …

Jul 13, 2026
CVE-2026-15525
6.3 MEDIUM

A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the …

Jul 13, 2026
CVE-2026-15524
3.3 LOW

A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of the file list-project-files-validation-factory.ts. Such manipulation of the …

Jul 13, 2026
CVE-2026-15523
6.3 MEDIUM

A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. …

Jul 13, 2026
CVE-2026-15522
5.3 MEDIUM

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component …

Jul 13, 2026
CVE-2026-15521
5.3 MEDIUM

A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. The manipulation …

Jul 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.