CVE Database

5195+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-15694
3.5 LOW

The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, …

Sep 5, 2026
CVE-2025-15693
2.7 LOW

The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the …

Sep 5, 2026
CVE-2026-86141
2.9 LOW

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after …

Sep 5, 2026
CVE-2026-86137
2.9 LOW

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

Sep 5, 2026
CVE-2026-85704
3.7 LOW

A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component …

Sep 4, 2026
CVE-2026-18540
3.7 LOW

undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the …

Sep 4, 2026
CVE-2026-85008
3.7 LOW

undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by subtracting the configured methods from …

Sep 4, 2026
CVE-2026-84947
3.7 LOW

undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares a Content-Length that exceeds the maximum, …

Sep 4, 2026
CVE-2026-18858
3.3 LOW

IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

Sep 4, 2026
CVE-2026-85592
3.7 LOW

phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddingQuestionsAllowed() method grants access to all callers when main.enableAskQuestions is …

Sep 4, 2026
CVE-2026-84066
3.1 LOW

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified …

Sep 4, 2026
CVE-2026-84438
3.5 LOW

A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the …

Sep 2, 2026
CVE-2026-84437
3.5 LOW

A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation …

Sep 2, 2026
CVE-2026-84368
3.7 LOW

joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor …

Sep 1, 2026
CVE-2026-84367
3.7 LOW

joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits …

Sep 1, 2026
CVE-2026-84307
3.7 LOW

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5, packages/panels/src/Auth/Pages/Login.php presents the multi-factor authentication challenge before evaluating …

Sep 1, 2026
CVE-2026-73748
2.2 LOW

A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. …

Sep 1, 2026
CVE-2026-73747
2.5 LOW

A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access …

Sep 1, 2026
CVE-2026-73746
3.1 LOW

A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial …

Sep 1, 2026
CVE-2026-73745
3.1 LOW

A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to view some information handled by the affected …

Sep 1, 2026
CVE-2026-73744
3.5 LOW

A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause …

Sep 1, 2026
CVE-2026-73743
3.7 LOW

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to gain insight into some data handled …

Sep 1, 2026
CVE-2026-81846
3.5 LOW

An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through …

Sep 1, 2026
CVE-2023-54356
3.7 LOW

Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the …

Sep 1, 2026
CVE-2026-48932
3.7 LOW

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while …

Sep 1, 2026
CVE-2026-18743
2.5 LOW

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead …

Sep 1, 2026
CVE-2026-77351
3.5 LOW

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private …

Aug 31, 2026
CVE-2026-82906
3.7 LOW

A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File …

Aug 31, 2026
CVE-2026-14367
3.1 LOW

The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchronization. The …

Aug 31, 2026
CVE-2023-31308
3.3 LOW

A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.

Aug 31, 2026
CVE-2026-82810
3.3 LOW

A weakness has been identified in extension.vn 2FA Authenticator Extension 1.0.0.2 on Chrome. The impacted element is the function chrome.runtime.onMessageExternal.addListener of the component Background Service …

Aug 31, 2026
CVE-2026-21827
3.1 LOW

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to, caused by …

Aug 31, 2026
CVE-2026-82699
2.7 LOW

A flaw has been found in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This impacts an unknown function of the file aca.sql of the component …

Aug 31, 2026
CVE-2026-82697
3.7 LOW

A security vulnerability has been detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. The impacted element is the function session_start. Such manipulation leads to cookie without …

Aug 31, 2026
CVE-2026-82677
2.4 LOW

A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation …

Aug 31, 2026
CVE-2026-82671
3.4 LOW

A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The …

Aug 31, 2026
CVE-2026-82863
3.3 LOW

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without …

Aug 31, 2026
CVE-2026-82665
3.8 LOW

A vulnerability was detected in yaojingang GEOFlow up to 2.1.0. This vulnerability affects the function unlink of the file app/Http/Controllers/Admin/ImageLibraryController.php of the component Image Library …

Aug 31, 2026
CVE-2026-82631
2.2 LOW

A security flaw has been discovered in valkey-io valkey 9.1.0. The affected element is the function handleClientsBlockedOnKey of the file src/blocked.c of the component Blocked-on-keys …

Aug 31, 2026
CVE-2026-82622
3.5 LOW

A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component …

Aug 31, 2026
CVE-2026-82596
3.3 LOW

A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. …

Aug 31, 2026
CVE-2026-82555
3.7 LOW

A vulnerability has been found in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function loginAuth of the file /web_cste/cgi-bin/cstecgi.cgi of the component Authentication Handler. Such …

Aug 30, 2026
CVE-2026-82656
2.6 LOW

Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments …

Aug 30, 2026
CVE-2026-82488
3.5 LOW

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads …

Aug 30, 2026
CVE-2026-82483
3.5 LOW

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden …

Aug 30, 2026
CVE-2026-82482
3.5 LOW

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the …

Aug 30, 2026
CVE-2026-78364
3.5 LOW

The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin …

Aug 30, 2026
CVE-2026-82562
3.7 LOW

### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array …

Aug 30, 2026
CVE-2026-81200
2.7 LOW

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to …

Aug 29, 2026
CVE-2026-77704
2.7 LOW

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change …

Aug 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.