CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-59237

Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated …

Jul 16, 2026
CVE-2026-14254

A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login …

Jul 16, 2026
CVE-2026-5674
8.8 HIGH

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio …

Jul 16, 2026
CVE-2026-56456
5.3 MEDIUM

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory …

Jul 16, 2026
CVE-2026-56455
5.3 MEDIUM

HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input …

Jul 16, 2026
CVE-2026-56454
5.9 MEDIUM

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic …

Jul 16, 2026
CVE-2026-56453
5.5 MEDIUM

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP …

Jul 16, 2026
CVE-2026-35145
3.1 LOW

HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its …

Jul 16, 2026
CVE-2026-35143
3.0 LOW

HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which …

Jul 16, 2026
CVE-2026-35142
2.6 LOW

HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could …

Jul 16, 2026
CVE-2026-35141
2.6 LOW

HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data …

Jul 16, 2026
CVE-2026-35140
3.0 LOW

HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session …

Jul 16, 2026
CVE-2026-9494
5.5 MEDIUM

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During …

Jul 16, 2026
CVE-2026-63306
8.6 HIGH

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or …

Jul 16, 2026
CVE-2026-63305
8.1 HIGH

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without …

Jul 16, 2026
CVE-2026-63304
8.1 HIGH

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers …

Jul 16, 2026
CVE-2026-12391
5.0 MEDIUM

An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file …

Jul 16, 2026
CVE-2026-11386
9.0 CRITICAL

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) …

Jul 16, 2026
CVE-2025-71388

stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, …

Jul 16, 2026
CVE-2025-71377

stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can …

Jul 16, 2026
CVE-2024-58360
6.5 MEDIUM

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with …

Jul 16, 2026
CVE-2026-59249

Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint …

Jul 16, 2026
CVE-2026-35149
8.2 HIGH

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting …

Jul 16, 2026
CVE-2026-35148
6.3 MEDIUM

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another …

Jul 16, 2026
CVE-2026-35147
8.2 HIGH

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific …

Jul 16, 2026
CVE-2026-35146
6.3 MEDIUM

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could …

Jul 16, 2026
CVE-2023-49900
9.8 CRITICAL

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

Jul 16, 2026
CVE-2023-49899
9.8 CRITICAL

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

Jul 16, 2026
CVE-2026-22752
9.6 CRITICAL

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through …

Jul 16, 2026
CVE-2026-7543
7.2 HIGH

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient …

Jul 16, 2026
CVE-2026-6424

Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system

Jul 16, 2026
CVE-2026-6423

A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authentication in an IPC channel.

Jul 16, 2026
CVE-2026-58078

The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

Jul 16, 2026
CVE-2026-15727
4.9 MEDIUM

The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 …

Jul 16, 2026
CVE-2026-15651
4.9 MEDIUM

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, …

Jul 16, 2026
CVE-2026-15610
4.3 MEDIUM

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 16, 2026
CVE-2026-15407
4.3 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin …

Jul 16, 2026
CVE-2026-15350
4.3 MEDIUM

The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the …

Jul 16, 2026
CVE-2026-15324
4.4 MEDIUM

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter …

Jul 16, 2026
CVE-2026-15106
5.3 MEDIUM

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 16, 2026
CVE-2026-15103
8.8 HIGH

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update …

Jul 16, 2026
CVE-2026-15099
6.4 MEDIUM

The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This …

Jul 16, 2026
CVE-2026-15022
6.5 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all …

Jul 16, 2026
CVE-2026-15021
6.4 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due …

Jul 16, 2026
CVE-2026-15008
8.1 HIGH

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file …

Jul 16, 2026
CVE-2026-15005
8.8 HIGH

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing …

Jul 16, 2026
CVE-2026-13767
6.5 MEDIUM

The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This …

Jul 16, 2026
CVE-2026-13755
6.4 MEDIUM

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up …

Jul 16, 2026
CVE-2026-13754
6.5 MEDIUM

The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up …

Jul 16, 2026
CVE-2026-13741
8.8 HIGH

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.