CVE Database

135211+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-5137
4.3 MEDIUM

The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path …

Jul 3, 2026
CVE-2026-4322
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows Reflected XSS. …

Jul 3, 2026
CVE-2026-4321
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows …

Jul 3, 2026
CVE-2026-9756
6.4 MEDIUM

The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, and including, …

Jul 3, 2026
CVE-2026-4804
6.4 MEDIUM

The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is …

Jul 3, 2026
CVE-2026-47896
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 through …

Jul 3, 2026
CVE-2026-35159
5.3 MEDIUM

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to …

Jul 3, 2026
CVE-2026-11900
4.3 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including …

Jul 3, 2026
CVE-2026-11778
5.4 MEDIUM

The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions …

Jul 3, 2026
CVE-2026-11398
5.3 MEDIUM

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Jul 3, 2026
CVE-2026-9230
4.3 MEDIUM

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 3, 2026
CVE-2026-9148
7.2 HIGH

The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, …

Jul 3, 2026
CVE-2026-8804

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, …

Jul 3, 2026
CVE-2026-8351
6.4 MEDIUM

The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in versions up to, and including, …

Jul 3, 2026
CVE-2026-47898
9.8 CRITICAL

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended …

Jul 3, 2026
CVE-2026-47897
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). This issue affects Apache Lucene.Net.Replicator: from 4.8.0-beta00005 before …

Jul 3, 2026
CVE-2026-14544
9.8 CRITICAL

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to …

Jul 3, 2026
CVE-2026-9547
7.4 HIGH

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs …

Jul 3, 2026
CVE-2026-9546
7.5 HIGH

A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses …

Jul 3, 2026
CVE-2026-9545
7.5 HIGH

In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site …

Jul 3, 2026
CVE-2026-9080
7.3 HIGH

Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after …

Jul 3, 2026
CVE-2026-9079
9.8 CRITICAL

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get …

Jul 3, 2026
CVE-2026-8932
7.5 HIGH

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously …

Jul 3, 2026
CVE-2026-8927
9.1 CRITICAL

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if …

Jul 3, 2026
CVE-2026-8926
9.1 CRITICAL

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like …

Jul 3, 2026
CVE-2026-8925
9.8 CRITICAL

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it …

Jul 3, 2026
CVE-2026-8924
9.1 CRITICAL

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables …

Jul 3, 2026
CVE-2026-8458
6.5 MEDIUM

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different 'services'. libcurl …

Jul 3, 2026
CVE-2026-8286
8.1 HIGH

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration …

Jul 3, 2026
CVE-2026-4967
7.5 HIGH

In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Jul 3, 2026
CVE-2026-12064
7.5 HIGH

When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The …

Jul 3, 2026
CVE-2026-11856
9.8 CRITICAL

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one …

Jul 3, 2026
CVE-2026-11586
7.5 HIGH

By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can …

Jul 3, 2026
CVE-2026-11564
9.1 CRITICAL

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that …

Jul 3, 2026
CVE-2026-11352
7.5 HIGH

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl …

Jul 3, 2026
CVE-2026-10536
9.8 CRITICAL

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the …

Jul 3, 2026
CVE-2026-9725
9.1 CRITICAL

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 …

Jul 3, 2026
CVE-2026-9626
6.4 MEDIUM

The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up …

Jul 3, 2026
CVE-2026-9180
5.3 MEDIUM

The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This is …

Jul 3, 2026
CVE-2026-8892
6.4 MEDIUM

The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in …

Jul 3, 2026
CVE-2026-8489
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 3, 2026
CVE-2026-14352
7.5 HIGH

The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. …

Jul 3, 2026
CVE-2026-13040
7.2 HIGH

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up …

Jul 3, 2026
CVE-2026-12557
5.3 MEDIUM

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due …

Jul 3, 2026
CVE-2026-11397
5.5 MEDIUM

The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_import_upload_file_from_url …

Jul 3, 2026
CVE-2026-8921

External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a …

Jul 3, 2026
CVE-2026-12960

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a crafted Intent …

Jul 3, 2026
CVE-2022-4990

** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass …

Jul 3, 2026
CVE-2022-4989

** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access …

Jul 3, 2026
CVE-2026-14327
7.5 HIGH

The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter parameter. …

Jul 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.