CVE Database

135497+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-54831
9.3 CRITICAL

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

Jun 26, 2026
CVE-2026-54827
9.3 CRITICAL

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

Jun 26, 2026
CVE-2026-54826
7.6 HIGH

Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.

Jun 26, 2026
CVE-2026-54825
9.3 CRITICAL

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

Jun 26, 2026
CVE-2026-54824
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

Jun 26, 2026
CVE-2026-54820
9.3 CRITICAL

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

Jun 26, 2026
CVE-2026-52701
6.5 MEDIUM

Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

Jun 26, 2026
CVE-2026-4339
6.5 MEDIUM

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost …

Jun 26, 2026
CVE-2026-45257
7.8 HIGH

The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does …

Jun 26, 2026
CVE-2026-45256
5.5 MEDIUM

When used to deliver a signal to a specific thread, thr_kill2(2) called p_cansignal() to determine whether the operation was permitted but did not check the …

Jun 26, 2026
CVE-2026-3472
3.5 LOW

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, …

Jun 26, 2026
CVE-2026-30041
7.5 HIGH

An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service …

Jun 26, 2026
CVE-2026-30040
6.5 MEDIUM

A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the …

Jun 26, 2026
CVE-2026-24547
5.3 MEDIUM

Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.

Jun 26, 2026
CVE-2025-68075
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

Jun 26, 2026
CVE-2025-68074
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

Jun 26, 2026
CVE-2025-68064
7.5 HIGH

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

Jun 26, 2026
CVE-2025-68063
7.5 HIGH

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

Jun 26, 2026
CVE-2025-68052
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

Jun 26, 2026
CVE-2025-66123
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

Jun 26, 2026
CVE-2025-64637
5.3 MEDIUM

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

Jun 26, 2026
CVE-2025-64636
5.3 MEDIUM

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

Jun 26, 2026
CVE-2025-63079
4.3 MEDIUM

Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.

Jun 26, 2026
CVE-2025-63078
4.3 MEDIUM

Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.

Jun 26, 2026
CVE-2025-63041
5.4 MEDIUM

Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

Jun 26, 2026
CVE-2026-57940

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to …

Jun 26, 2026
CVE-2026-57926
2.6 LOW

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Jun 26, 2026
CVE-2026-57925
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

Jun 26, 2026
CVE-2026-57924
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

Jun 26, 2026
CVE-2026-57923
5.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

Jun 26, 2026
CVE-2026-57922
3.1 LOW

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

Jun 26, 2026
CVE-2026-57921
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

Jun 26, 2026
CVE-2026-53914
6.7 MEDIUM

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Jun 26, 2026
CVE-2026-13426
5.4 MEDIUM

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API …

Jun 26, 2026
CVE-2026-57920
7.7 HIGH

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

Jun 26, 2026
CVE-2026-57915
7.3 HIGH

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended …

Jun 26, 2026
CVE-2026-40711
8.0 HIGH

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS …

Jun 26, 2026
CVE-2025-64152
9.1 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from …

Jun 26, 2026
CVE-2025-55017
9.1 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from …

Jun 26, 2026
CVE-2026-57914
6.5 MEDIUM

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to …

Jun 26, 2026
CVE-2026-57620
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS. This issue affects Exclusive Addons …

Jun 26, 2026
CVE-2026-57918
7.1 HIGH

libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when …

Jun 26, 2026
CVE-2026-57913
7.5 HIGH

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.

Jun 26, 2026
CVE-2026-57912
7.5 HIGH

Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.

Jun 26, 2026
CVE-2026-57473

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the …

Jun 26, 2026
CVE-2026-13325
8.5 HIGH

A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain …

Jun 26, 2026
CVE-2025-7958

A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface …

Jun 26, 2026
CVE-2026-6658
5.4 MEDIUM

A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders …

Jun 26, 2026
CVE-2026-1869
6.5 MEDIUM

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is …

Jun 26, 2026
CVE-2026-11702
7.5 HIGH

Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state for the …

Jun 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.