CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-5092
6.4 MEDIUM

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up …

Aug 26, 2026
CVE-2026-3235
5.3 MEDIUM

The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' …

Aug 26, 2026
CVE-2026-2388
6.4 MEDIUM

The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This …

Aug 26, 2026
CVE-2026-80234
5.3 MEDIUM

CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting …

Aug 26, 2026
CVE-2026-19197
6.3 MEDIUM

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret …

Aug 26, 2026
CVE-2026-9668
6.3 MEDIUM

With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently …

Aug 26, 2026
CVE-2026-6178
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's 'icon_box_2' shortcode in all versions up to, and including, 28.4 due …

Aug 26, 2026
CVE-2026-3002
6.4 MEDIUM

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all …

Aug 26, 2026
CVE-2026-79654
4.3 MEDIUM

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the …

Aug 26, 2026
CVE-2026-78146
6.5 MEDIUM

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named in a public request before rendering that …

Aug 26, 2026
CVE-2026-77789
4.3 MEDIUM

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not verify that a subscription belongs to the customer bound to the …

Aug 26, 2026
CVE-2026-77758
5.3 MEDIUM

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal session has completed its confirmation …

Aug 26, 2026
CVE-2026-77757
5.4 MEDIUM

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitize a user-supplied image reference before using it as the …

Aug 26, 2026
CVE-2026-77754
5.3 MEDIUM

The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJAX actions, allowing unauthenticated users …

Aug 26, 2026
CVE-2026-77695
6.5 MEDIUM

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of guest orders in some of the AJAX …

Aug 26, 2026
CVE-2026-77694
5.3 MEDIUM

The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed to authorise on an order, allowing unauthenticated …

Aug 26, 2026
CVE-2026-75798
5.3 MEDIUM

The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it …

Aug 26, 2026
CVE-2026-74930
4.3 MEDIUM

The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in …

Aug 26, 2026
CVE-2026-74929
5.4 MEDIUM

The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any …

Aug 26, 2026
CVE-2026-19226
6.8 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow …

Aug 26, 2026
CVE-2026-19094
5.3 MEDIUM

The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a …

Aug 26, 2026
CVE-2026-16986
5.3 MEDIUM

The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied …

Aug 26, 2026
CVE-2026-16984
6.5 MEDIUM

The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on …

Aug 26, 2026
CVE-2026-14550
5.3 MEDIUM

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available …

Aug 26, 2026
CVE-2026-14216
6.5 MEDIUM

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user …

Aug 26, 2026
CVE-2026-14212
4.7 MEDIUM

The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, …

Aug 26, 2026
CVE-2026-13406
5.3 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, …

Aug 26, 2026
CVE-2026-13404
5.3 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing …

Aug 26, 2026
CVE-2026-13172
5.3 MEDIUM

The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing …

Aug 26, 2026
CVE-2026-80200
4.7 MEDIUM

Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with …

Aug 26, 2026
CVE-2026-80197
4.3 MEDIUM

Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. …

Aug 26, 2026
CVE-2026-80195
5.4 MEDIUM

Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members …

Aug 26, 2026
CVE-2026-80194
4.3 MEDIUM

Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather …

Aug 26, 2026
CVE-2026-80189
6.5 MEDIUM

LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the …

Aug 26, 2026
CVE-2026-76149
4.4 MEDIUM

CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.

Aug 26, 2026
CVE-2026-73335
5.3 MEDIUM

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device …

Aug 26, 2026
CVE-2026-70665
4.2 MEDIUM

Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint …

Aug 25, 2026
CVE-2026-55805
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from …

Aug 25, 2026
CVE-2026-18261
5.7 MEDIUM

Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.

Aug 25, 2026
CVE-2026-18260
5.7 MEDIUM

Vulnerability in Drupal Disable Login Page. This issue affects Disable Login Page versions: *.*.

Aug 25, 2026
CVE-2026-16646
5.7 MEDIUM

Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

Aug 25, 2026
CVE-2026-16643
5.7 MEDIUM

Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.

Aug 25, 2026
CVE-2026-16642
5.7 MEDIUM

Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.

Aug 25, 2026
CVE-2026-16640
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete …

Aug 25, 2026
CVE-2026-16638
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from …

Aug 25, 2026
CVE-2026-15917
4.7 MEDIUM

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: …

Aug 25, 2026
CVE-2026-15916
4.2 MEDIUM

Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from …

Aug 25, 2026
CVE-2026-15088
5.7 MEDIUM

Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.

Aug 25, 2026
CVE-2026-80185
5.7 MEDIUM

BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union …

Aug 25, 2026
CVE-2026-73180
6.8 MEDIUM

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.