CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-85517
5.3 MEDIUM

A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component …

Sep 4, 2026
CVE-2026-77818
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library …

Sep 4, 2026
CVE-2026-19081
4.3 MEDIUM

Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gastromenum Ticket and …

Sep 4, 2026
CVE-2026-19057
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects …

Sep 4, 2026
CVE-2026-85514
6.3 MEDIUM

A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API …

Sep 4, 2026
CVE-2026-85513
6.3 MEDIUM

A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp …

Sep 4, 2026
CVE-2026-82309
4.3 MEDIUM

Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names …

Sep 4, 2026
CVE-2026-74237
6.5 MEDIUM

GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command …

Sep 4, 2026
CVE-2026-74236
6.5 MEDIUM

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with …

Sep 4, 2026
CVE-2026-74235
4.9 MEDIUM

GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed …

Sep 4, 2026
CVE-2026-85615
6.4 MEDIUM

Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized …

Sep 4, 2026
CVE-2026-85611
6.4 MEDIUM

OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to …

Sep 4, 2026
CVE-2026-85603
6.5 MEDIUM

Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An …

Sep 4, 2026
CVE-2026-85602
5.3 MEDIUM

The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in …

Sep 4, 2026
CVE-2026-85601
5.4 MEDIUM

Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. …

Sep 4, 2026
CVE-2026-85600
5.4 MEDIUM

Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into …

Sep 4, 2026
CVE-2026-85598
6.4 MEDIUM

Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attackers with …

Sep 4, 2026
CVE-2026-85593
5.4 MEDIUM

phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ content, reversing entity-encoding protection. Authenticated users with …

Sep 4, 2026
CVE-2026-85583
6.5 MEDIUM

SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. Attackers with reader …

Sep 4, 2026
CVE-2026-85582
6.5 MEDIUM

SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust memory. Attackers can …

Sep 4, 2026
CVE-2026-85580
6.5 MEDIUM

SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can read …

Sep 4, 2026
CVE-2026-85579
4.3 MEDIUM

SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The endpoint returns the peekMutatedRootIDs …

Sep 4, 2026
CVE-2026-85578
6.5 MEDIUM

SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly configured as Visible:false. Attackers …

Sep 4, 2026
CVE-2026-85577
5.4 MEDIUM

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag …

Sep 4, 2026
CVE-2026-19043
4.3 MEDIUM

Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Portal: before 20260903211448.

Sep 4, 2026
CVE-2026-18957
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue affects Menulux Portal: …

Sep 4, 2026
CVE-2026-85534
5.9 MEDIUM

A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data …

Sep 4, 2026
CVE-2026-84045
5.3 MEDIUM

The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before …

Sep 4, 2026
CVE-2026-27347
5.3 MEDIUM

Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2.

Sep 4, 2026
CVE-2026-85541
5.4 MEDIUM

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

Sep 4, 2026
CVE-2026-84044
5.3 MEDIUM

The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers …

Sep 4, 2026
CVE-2026-84043
5.3 MEDIUM

The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticated attackers to mark …

Sep 4, 2026
CVE-2026-81666
6.5 MEDIUM

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems …

Sep 4, 2026
CVE-2026-27086
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: from n/a before 8.3.8.

Sep 4, 2026
CVE-2026-85528
5.3 MEDIUM

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to …

Sep 4, 2026
CVE-2026-85311
5.3 MEDIUM

Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60.

Sep 4, 2026
CVE-2026-32480
5.3 MEDIUM

Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11.

Sep 4, 2026
CVE-2026-27432
5.4 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: …

Sep 4, 2026
CVE-2026-85229
6.1 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache …

Sep 4, 2026
CVE-2026-80190
6.1 MEDIUM

Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability is likely mitigated via default CSP headers. …

Sep 4, 2026
CVE-2026-6217
6.3 MEDIUM

Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online …

Sep 4, 2026
CVE-2026-84146
5.3 MEDIUM

The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product …

Sep 4, 2026
CVE-2026-82194
5.5 MEDIUM

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion …

Sep 4, 2026
CVE-2026-82193
5.5 MEDIUM

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a …

Sep 4, 2026
CVE-2026-82186
4.1 MEDIUM

The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with …

Sep 4, 2026
CVE-2026-81347
5.9 MEDIUM

The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers …

Sep 4, 2026
CVE-2026-80438
5.9 MEDIUM

The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as …

Sep 4, 2026
CVE-2026-80180
6.1 MEDIUM

Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, …

Sep 4, 2026
CVE-2026-79632
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification …

Sep 4, 2026
CVE-2026-79631
5.3 MEDIUM

The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, …

Sep 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.