CVE Database

134505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9253
7.2 HIGH

The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all …

Jul 9, 2026
CVE-2026-15182
5.3 MEDIUM

A vulnerability has been found in GNU LibreDWG up to 0.13.4. The affected element is the function dwg_bmp of the file src/dwg.c of the component …

Jul 9, 2026
CVE-2026-9240
4.3 MEDIUM

The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Jul 9, 2026
CVE-2026-9237
4.3 MEDIUM

The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Jul 9, 2026
CVE-2026-9235
4.3 MEDIUM

The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and …

Jul 9, 2026
CVE-2026-9028
5.3 MEDIUM

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to …

Jul 9, 2026
CVE-2026-9027
5.3 MEDIUM

The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, and …

Jul 9, 2026
CVE-2026-9021
5.3 MEDIUM

The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering …

Jul 9, 2026
CVE-2026-59692
7.5 HIGH

A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a …

Jul 9, 2026
CVE-2026-59691
7.1 HIGH

A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer …

Jul 9, 2026
CVE-2026-58307
6.1 MEDIUM

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.

Jul 9, 2026
CVE-2026-58306
6.1 MEDIUM

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.

Jul 9, 2026
CVE-2026-58305
6.1 MEDIUM

Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

Jul 9, 2026
CVE-2026-58304
6.1 MEDIUM

Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.

Jul 9, 2026
CVE-2026-58303
6.1 MEDIUM

Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.

Jul 9, 2026
CVE-2026-56291
9.8 CRITICAL KEV

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jul 9, 2026
CVE-2026-56289
5.5 MEDIUM

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in …

Jul 9, 2026
CVE-2026-56288
5.5 MEDIUM

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can …

Jul 9, 2026
CVE-2026-50644

SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form …

Jul 9, 2026
CVE-2026-4298
4.3 MEDIUM

The DSGVO All in one for WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 4.9. This is …

Jul 9, 2026
CVE-2026-4275
8.8 HIGH

The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jul 9, 2026
CVE-2026-14372
7.1 HIGH

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion …

Jul 9, 2026
CVE-2026-13441
7.2 HIGH

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'new_event_type_background_color' parameter in all versions up …

Jul 9, 2026
CVE-2026-12590
3.7 LOW

Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such …

Jul 9, 2026
CVE-2026-12428
6.5 MEDIUM

The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function …

Jul 9, 2026
CVE-2026-5955
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue …

Jul 9, 2026
CVE-2026-5793
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: …

Jul 9, 2026
CVE-2026-56460
6.5 MEDIUM

HCL DevOps Deploy / HCL Launch could disclose sensitive configurations and secrets to authenticated users in API responses that could be used in further attacks …

Jul 9, 2026
CVE-2026-56459
6.2 MEDIUM

HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log files that could be read …

Jul 9, 2026
CVE-2026-56458
5.4 MEDIUM

HCL DevOps Deploy uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain …

Jul 9, 2026
CVE-2026-2342
9.3 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through …

Jul 9, 2026
CVE-2026-1989
7.5 HIGH

Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Identifiers. This issue affects PAVO Pay: through …

Jul 9, 2026
CVE-2026-1365
6.5 MEDIUM

Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The …

Jul 9, 2026
CVE-2026-15158
9.8 CRITICAL

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This …

Jul 9, 2026
CVE-2026-12433
4.3 MEDIUM

The Hydra Booking – Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, …

Jul 9, 2026
CVE-2026-8996
6.5 MEDIUM

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 …

Jul 9, 2026
CVE-2026-8848
7.2 HIGH

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all …

Jul 9, 2026
CVE-2026-7558
5.3 MEDIUM

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including …

Jul 9, 2026
CVE-2026-6910
6.4 MEDIUM

The Bookero.pl – system rezerwacji online plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookero_products` shortcode's `hide_products` (and `filter_products`) attributes in versions …

Jul 9, 2026
CVE-2026-59269
3.8 LOW

A user authenticating to Kubernetes clusters via the Pinniped Supervisor could potentially gain elevated permissions in the clusters, only if all the following conditions were …

Jul 9, 2026
CVE-2026-57111
7.5 HIGH

Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a …

Jul 9, 2026
CVE-2026-4653
6.4 MEDIUM

The Block, Suspend, Report for BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter in versions up to and including …

Jul 9, 2026
CVE-2026-33390
8.1 HIGH

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can …

Jul 9, 2026
CVE-2026-31985
8.1 HIGH

When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was …

Jul 9, 2026
CVE-2026-31984
7.5 HIGH

A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into …

Jul 9, 2026
CVE-2026-31983
5.3 MEDIUM

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint …

Jul 9, 2026
CVE-2026-31982
7.1 HIGH

An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can …

Jul 9, 2026
CVE-2026-31981
5.9 MEDIUM

A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An …

Jul 9, 2026
CVE-2026-15000
7.2 HIGH

The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up …

Jul 9, 2026
CVE-2026-14343
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, …

Jul 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.