CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-39070
4.8 MEDIUM

WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exploit …

Aug 28, 2026
CVE-2026-82330
6.1 MEDIUM

A flaw was found in the file-pvr plugin in GIMP. When processing a specially crafted PVR image file, the VQ (compressed) decoder does not properly …

Aug 28, 2026
CVE-2026-82328
6.1 MEDIUM

A flaw was found in the file-ico plugin in GIMP. When processing a specially crafted ICO image file, the plugin does not properly validate the …

Aug 28, 2026
CVE-2026-82327
5.5 MEDIUM

A flaw was found in libsolv, a dependency-resolution library used by RPM-based package managers such as dnf and zypper to work with .solv repository cache …

Aug 28, 2026
CVE-2026-82324
6.1 MEDIUM

A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When processing a specially crafted IFF/ILBM image file, the plugin does not properly validate …

Aug 28, 2026
CVE-2026-82220
5.3 MEDIUM

Unauthenticated Other Vulnerability Type in Forminator <= 1.57.1 versions.

Aug 28, 2026
CVE-2026-82181
5.5 MEDIUM

Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history …

Aug 28, 2026
CVE-2026-81761
4.3 MEDIUM

Subscriber Broken Access Control in WpEvently <= 5.5.0 versions.

Aug 28, 2026
CVE-2026-81759
5.4 MEDIUM

Contributor Broken Access Control in WpEvently <= 5.5.0 versions.

Aug 28, 2026
CVE-2026-81341
6.5 MEDIUM

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence …

Aug 28, 2026
CVE-2026-81299
4.3 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in WP Job Portal <= 2.5.9 versions.

Aug 28, 2026
CVE-2026-81284
4.3 MEDIUM

Contributor Broken Access Control in ACF Extended <= 0.9.2.6 versions.

Aug 28, 2026
CVE-2026-5953
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: …

Aug 28, 2026
CVE-2026-5800
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue …

Aug 28, 2026
CVE-2026-5096
5.3 MEDIUM

The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the …

Aug 28, 2026
CVE-2026-4378
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects …

Aug 28, 2026
CVE-2026-3423
6.4 MEDIUM

The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, …

Aug 28, 2026
CVE-2026-38725
5.4 MEDIUM

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input …

Aug 28, 2026
CVE-2026-37710
6.1 MEDIUM

Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function

Aug 28, 2026
CVE-2026-15603
5.3 MEDIUM

morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize …

Aug 28, 2026
CVE-2026-82258
4.8 MEDIUM

SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request …

Aug 28, 2026
CVE-2026-82257
4.3 MEDIUM

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can …

Aug 28, 2026
CVE-2026-82256
5.3 MEDIUM

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation …

Aug 28, 2026
CVE-2026-82255
6.8 MEDIUM

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. …

Aug 28, 2026
CVE-2026-82250
6.5 MEDIUM

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious …

Aug 28, 2026
CVE-2026-82248
5.3 MEDIUM

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: …

Aug 28, 2026
CVE-2026-82235
5.9 MEDIUM

filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or …

Aug 28, 2026
CVE-2026-82233
5.7 MEDIUM

SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can …

Aug 28, 2026
CVE-2026-82111
4.3 MEDIUM

A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. …

Aug 28, 2026
CVE-2026-81777
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.

Aug 28, 2026
CVE-2026-73209
6.5 MEDIUM

An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process …

Aug 28, 2026
CVE-2026-6128
6.4 MEDIUM

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and …

Aug 28, 2026
CVE-2026-5510
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up …

Aug 28, 2026
CVE-2026-52687
6.5 MEDIUM

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and …

Aug 28, 2026
CVE-2026-42395
4.3 MEDIUM

A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. …

Aug 28, 2026
CVE-2026-42392
4.3 MEDIUM

An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned …

Aug 28, 2026
CVE-2026-42008
4.3 MEDIUM

Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by …

Aug 28, 2026
CVE-2026-40205
5.9 MEDIUM

An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more than one scope is required in …

Aug 28, 2026
CVE-2026-40019
5.9 MEDIUM

An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin in an infinite loop consuming CPU. This …

Aug 28, 2026
CVE-2026-40017
6.5 MEDIUM

An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal hash table, …

Aug 28, 2026
CVE-2026-40015
4.3 MEDIUM

An attacker that has valid credentials can open many connections to the imap-hibernate service and send invalid commands, which can intermittently cause an out-of-bounds read …

Aug 28, 2026
CVE-2026-40014
6.5 MEDIUM

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU disproportionate to the …

Aug 28, 2026
CVE-2026-40013
4.3 MEDIUM

An attacker that has valid credentials can submit a Sieve script containing an extreme numeric literal, which causes an out-of-bounds write when the ManageSieve service …

Aug 28, 2026
CVE-2026-33607
4.3 MEDIUM

An attacker that has valid credentials can use IMAP LIST command to consume CPU. This can cause degradation or denial of service for IMAP. Monitor …

Aug 28, 2026
CVE-2026-33606
4.8 MEDIUM

Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator later runs dsync with …

Aug 28, 2026
CVE-2026-33604
5.9 MEDIUM

An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in …

Aug 28, 2026
CVE-2026-33263
4.3 MEDIUM

When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with epoll() panic caused by file descriptor handling issues. If running in high-security mode …

Aug 28, 2026
CVE-2026-18393
5.4 MEDIUM

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote …

Aug 28, 2026
CVE-2026-9548
6.5 MEDIUM

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, …

Aug 28, 2026
CVE-2026-9491
4.3 MEDIUM

A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.