CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-64636
5.3 MEDIUM

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

Jun 26, 2026
CVE-2025-63079
4.3 MEDIUM

Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

Jun 26, 2026
CVE-2025-63078
4.3 MEDIUM

Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.

Jun 26, 2026
CVE-2025-63041
5.4 MEDIUM

Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

Jun 26, 2026
CVE-2026-57925
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

Jun 26, 2026
CVE-2026-57924
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Jun 26, 2026
CVE-2026-57923
5.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

Jun 26, 2026
CVE-2026-57921
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

Jun 26, 2026
CVE-2026-53914
6.7 MEDIUM

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Jun 26, 2026
CVE-2026-13426
5.4 MEDIUM

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API …

Jun 26, 2026
CVE-2026-57914
6.5 MEDIUM

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to …

Jun 26, 2026
CVE-2026-57620
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons …

Jun 26, 2026
CVE-2026-6658
5.4 MEDIUM

A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders …

Jun 26, 2026
CVE-2026-1869
6.5 MEDIUM

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is …

Jun 26, 2026
CVE-2026-8380
6.5 MEDIUM

The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with …

Jun 26, 2026
CVE-2025-10268
5.3 MEDIUM

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible for the attacker …

Jun 26, 2026
CVE-2026-8661
4.8 MEDIUM

Server-Side Cross-Site Scripting and Server-Side Request Forgery vulnerability in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin version 3.1.4 and earlier on Linux allows remote …

Jun 26, 2026
CVE-2026-50745
6.1 MEDIUM

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, …

Jun 26, 2026
CVE-2026-50744
4.3 MEDIUM

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID …

Jun 26, 2026
CVE-2026-50742
5.4 MEDIUM

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without …

Jun 26, 2026
CVE-2026-50740
5.4 MEDIUM

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh …

Jun 26, 2026
CVE-2026-50739
4.3 MEDIUM

A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the …

Jun 26, 2026
CVE-2026-48934
4.3 MEDIUM

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js …

Jun 26, 2026
CVE-2026-48928
5.4 MEDIUM

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js …

Jun 26, 2026
CVE-2026-48618
6.5 MEDIUM

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and …

Jun 26, 2026
CVE-2026-13226
6.5 MEDIUM

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in all versions up …

Jun 26, 2026
CVE-2026-9219
6.5 MEDIUM

Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional authentication before assignment. …

Jun 26, 2026
CVE-2026-13318
6.4 MEDIUM

A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api reads the …

Jun 26, 2026
CVE-2026-13218
4.2 MEDIUM

A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without symlink …

Jun 26, 2026
CVE-2026-13083
6.9 MEDIUM

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with …

Jun 26, 2026
CVE-2026-12993
6.5 MEDIUM

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. …

Jun 26, 2026
CVE-2026-40941
6.5 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed …

Jun 25, 2026
CVE-2026-40084
6.5 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing …

Jun 25, 2026
CVE-2026-40082
5.4 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is …

Jun 25, 2026
CVE-2026-40080
6.1 MEDIUM

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than …

Jun 25, 2026
CVE-2026-6330
6.5 MEDIUM

The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code …

Jun 25, 2026
CVE-2026-6329
6.5 MEDIUM

PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 …

Jun 25, 2026
CVE-2026-6092
5.3 MEDIUM

When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.

Jun 25, 2026
CVE-2026-55962
6.5 MEDIUM

TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The …

Jun 25, 2026
CVE-2026-44622
6.5 MEDIUM

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Jun 25, 2026
CVE-2026-13282
6.8 MEDIUM

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access …

Jun 25, 2026
CVE-2026-10098
5.3 MEDIUM

OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation …

Jun 25, 2026
CVE-2020-37256
5.4 MEDIUM

Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject …

Jun 25, 2026
CVE-2026-6681
5.3 MEDIUM

The PKCS#7 decode path ignores the caller-supplied output buffer size (outputSz), allowing decoded content to be written past the bounds of the provided buffer. This …

Jun 25, 2026
CVE-2026-6678
5.3 MEDIUM

Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.

Jun 25, 2026
CVE-2026-6450
5.3 MEDIUM

A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to …

Jun 25, 2026
CVE-2026-6412
4.3 MEDIUM

Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.

Jun 25, 2026
CVE-2026-57521
4.3 MEDIUM

Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary …

Jun 25, 2026
CVE-2026-55964
5.3 MEDIUM

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage …

Jun 25, 2026
CVE-2026-2299
4.2 MEDIUM

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated users with a connected Google …

Jun 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.