CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-53682
5.3 MEDIUM

An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security …

Sep 1, 2026
CVE-2026-51745
5.3 MEDIUM

Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT …

Sep 1, 2026
CVE-2026-51742
5.9 MEDIUM

Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request …

Sep 1, 2026
CVE-2026-84191
6.1 MEDIUM

LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. …

Sep 1, 2026
CVE-2026-84188
4.8 MEDIUM

LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr.<graphtype> configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An …

Sep 1, 2026
CVE-2026-77194
5.3 MEDIUM

The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is …

Sep 1, 2026
CVE-2026-11873
6.5 MEDIUM

An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same …

Sep 1, 2026
CVE-2026-10420
5.5 MEDIUM

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.

Sep 1, 2026
CVE-2025-15613
6.5 MEDIUM

Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify …

Sep 1, 2026
CVE-2026-82927
5.5 MEDIUM

Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.

Sep 1, 2026
CVE-2026-82926
5.5 MEDIUM

NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.

Sep 1, 2026
CVE-2026-16788
6.4 MEDIUM

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versions up to, …

Sep 1, 2026
CVE-2026-16786
6.4 MEDIUM

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all versions up to, …

Sep 1, 2026
CVE-2026-15101
6.4 MEDIUM

The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 …

Sep 1, 2026
CVE-2026-78363
4.8 MEDIUM

The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a …

Sep 1, 2026
CVE-2026-74916
6.5 MEDIUM

The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages …

Sep 1, 2026
CVE-2026-13611
5.3 MEDIUM

The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster …

Sep 1, 2026
CVE-2026-77189
6.5 MEDIUM

The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to generic SQL Injection via 'order' …

Sep 1, 2026
CVE-2026-75980
6.4 MEDIUM

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribute …

Sep 1, 2026
CVE-2026-75964
6.1 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Sep 1, 2026
CVE-2026-18488
6.4 MEDIUM

The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and including, 2.1.51 …

Sep 1, 2026
CVE-2026-83744
4.3 MEDIUM

A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/Pdf/Purify.php of the …

Sep 1, 2026
CVE-2026-83743
6.3 MEDIUM

A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor …

Sep 1, 2026
CVE-2026-77823
4.9 MEDIUM

The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, …

Sep 1, 2026
CVE-2026-76006
4.9 MEDIUM

The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions …

Sep 1, 2026
CVE-2026-75965
6.4 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Sep 1, 2026
CVE-2026-19948
5.3 MEDIUM

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization …

Sep 1, 2026
CVE-2026-18752
6.5 MEDIUM

The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to …

Sep 1, 2026
CVE-2026-17589
4.9 MEDIUM

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and …

Sep 1, 2026
CVE-2026-16787
6.4 MEDIUM

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to, …

Sep 1, 2026
CVE-2026-13203
6.4 MEDIUM

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_modules_section …

Sep 1, 2026
CVE-2026-12747
6.4 MEDIUM

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, …

Sep 1, 2026
CVE-2026-19032
5.3 MEDIUM

jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new …

Sep 1, 2026
CVE-2026-67395
5.9 MEDIUM

A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal …

Sep 1, 2026
CVE-2026-82396
5.4 MEDIUM

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and …

Aug 31, 2026
CVE-2026-77353
4.6 MEDIUM

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their …

Aug 31, 2026
CVE-2026-77352
4.3 MEDIUM

Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make …

Aug 31, 2026
CVE-2026-82909
4.3 MEDIUM

A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component …

Aug 31, 2026
CVE-2026-82852
5.4 MEDIUM

Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.

Aug 31, 2026
CVE-2026-81890
5.4 MEDIUM

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in …

Aug 31, 2026
CVE-2026-81888
5.4 MEDIUM

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is …

Aug 31, 2026
CVE-2026-81778
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.

Aug 31, 2026
CVE-2026-81762
6.5 MEDIUM

Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.

Aug 31, 2026
CVE-2026-81758
6.3 MEDIUM

Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.

Aug 31, 2026
CVE-2026-81280
6.5 MEDIUM

Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

Aug 31, 2026
CVE-2026-81278
5.4 MEDIUM

Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.

Aug 31, 2026
CVE-2026-79483
5.3 MEDIUM

FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators …

Aug 31, 2026
CVE-2026-75460
6.5 MEDIUM

XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully …

Aug 31, 2026
CVE-2026-54179
4.4 MEDIUM

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 …

Aug 31, 2026
CVE-2026-50199
4.3 MEDIUM

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.