CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9639
6.5 MEDIUM

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial …

Jun 26, 2026
CVE-2026-44018
5.5 MEDIUM

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing …

Jun 26, 2026
CVE-2026-9699
6.8 MEDIUM

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to …

Jun 26, 2026
CVE-2026-57665
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions.

Jun 26, 2026
CVE-2026-57664
4.3 MEDIUM

Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.

Jun 26, 2026
CVE-2026-57661
5.4 MEDIUM

Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.

Jun 26, 2026
CVE-2026-57660
5.3 MEDIUM

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.

Jun 26, 2026
CVE-2026-57657
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.

Jun 26, 2026
CVE-2026-57656
5.9 MEDIUM

Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.

Jun 26, 2026
CVE-2026-57654
6.5 MEDIUM

Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.

Jun 26, 2026
CVE-2026-57652
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.

Jun 26, 2026
CVE-2026-57651
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.

Jun 26, 2026
CVE-2026-57650
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.

Jun 26, 2026
CVE-2026-57649
4.3 MEDIUM

Subscriber Broken Access Control in Shoppable Images Lite <= 1.3 versions.

Jun 26, 2026
CVE-2026-57648
4.3 MEDIUM

Contributor Broken Access Control in Nelio Content <= 4.3.4 versions.

Jun 26, 2026
CVE-2026-57646
5.4 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.

Jun 26, 2026
CVE-2026-57641
6.5 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions.

Jun 26, 2026
CVE-2026-57640
4.3 MEDIUM

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.30 versions.

Jun 26, 2026
CVE-2026-57638
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.

Jun 26, 2026
CVE-2026-57637
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

Jun 26, 2026
CVE-2026-57635
6.5 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in FunnelKit Payment Gateway for Stripe WooCommerce <= 1.14.0.3 versions.

Jun 26, 2026
CVE-2026-57634
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in PPWP <= 1.9.19 versions.

Jun 26, 2026
CVE-2026-57633
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions.

Jun 26, 2026
CVE-2026-57632
5.4 MEDIUM

Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.

Jun 26, 2026
CVE-2026-57630
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Blocksy Companion Pro <= 2.1.46 versions.

Jun 26, 2026
CVE-2026-57629
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.

Jun 26, 2026
CVE-2026-57627
4.9 MEDIUM

Subscriber Server Side Request Forgery (SSRF) in Kirki <= 6.0.11 versions.

Jun 26, 2026
CVE-2026-57622
4.3 MEDIUM

Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.

Jun 26, 2026
CVE-2026-57618
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.

Jun 26, 2026
CVE-2026-57617
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in SeedProd Pro < 6.19.5 versions.

Jun 26, 2026
CVE-2026-57431
6.5 MEDIUM

Author Cross Site Scripting (XSS) in Featured Image <= 2.1 versions.

Jun 26, 2026
CVE-2026-57430
4.3 MEDIUM

Contributor Broken Access Control in SEOPress PRO <= 9.1.1 versions.

Jun 26, 2026
CVE-2026-57324
6.5 MEDIUM

Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.

Jun 26, 2026
CVE-2026-57323
5.8 MEDIUM

Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.

Jun 26, 2026
CVE-2026-57318
6.5 MEDIUM

Subscriber Sensitive Data Exposure in Site Reviews <= 8.0.11 versions.

Jun 26, 2026
CVE-2026-57316
6.5 MEDIUM

Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

Jun 26, 2026
CVE-2026-57313
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in SureCart <= 4.2.2 versions.

Jun 26, 2026
CVE-2026-56066
5.8 MEDIUM

Unauthenticated Arbitrary File Deletion in ShortPixel Adaptive Images <= 3.11.4 versions.

Jun 26, 2026
CVE-2026-56048
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.

Jun 26, 2026
CVE-2026-56046
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in ListingPro <= 2.9.11 versions.

Jun 26, 2026
CVE-2026-56026
6.4 MEDIUM

Subscriber Server Side Request Forgery (SSRF) in utm.codes <= 1.9.0 versions.

Jun 26, 2026
CVE-2026-52701
6.5 MEDIUM

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

Jun 26, 2026
CVE-2026-4339
6.5 MEDIUM

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost …

Jun 26, 2026
CVE-2026-45256
5.5 MEDIUM

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not check the …

Jun 26, 2026
CVE-2026-30040
6.5 MEDIUM

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the …

Jun 26, 2026
CVE-2026-24547
5.3 MEDIUM

Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.

Jun 26, 2026
CVE-2025-68075
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

Jun 26, 2026
CVE-2025-68074
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

Jun 26, 2026
CVE-2025-66123
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

Jun 26, 2026
CVE-2025-64637
5.3 MEDIUM

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

Jun 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.