CVE Database

135611+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11859

An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that …

Jun 10, 2026
CVE-2026-3018
7.5 HIGH

The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in all versions up to, and including, 4.13 due to …

Jun 10, 2026
CVE-2026-11853
6.5 MEDIUM

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that …

Jun 10, 2026
CVE-2026-11852
6.5 MEDIUM

Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create …

Jun 10, 2026
CVE-2025-6254
9.8 CRITICAL

The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8. This is due to the doctreat_process_registration() …

Jun 10, 2026
CVE-2026-9019
6.4 MEDIUM

The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters in all versions up to, and including, …

Jun 10, 2026
CVE-2026-8853
4.4 MEDIUM

The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 …

Jun 10, 2026
CVE-2026-8613
6.4 MEDIUM

The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, …

Jun 10, 2026
CVE-2026-10721

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may …

Jun 10, 2026
CVE-2026-9067
9.1 CRITICAL

The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and …

Jun 10, 2026
CVE-2026-9060
3.5 LOW

The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store …

Jun 10, 2026
CVE-2026-8071
8.8 HIGH

The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing …

Jun 10, 2026
CVE-2026-3326
8.6 HIGH

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action …

Jun 10, 2026
CVE-2026-29116

A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that …

Jun 10, 2026
CVE-2026-29115

A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that …

Jun 10, 2026
CVE-2026-29114

A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted …

Jun 10, 2026
CVE-2026-11815

An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could …

Jun 10, 2026
CVE-2026-10846

NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address …

Jun 10, 2026
CVE-2026-26241
9.1 CRITICAL

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash …

Jun 10, 2026
CVE-2026-26240
9.1 CRITICAL

A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to modify memory or crash …

Jun 10, 2026
CVE-2026-11837
7.3 HIGH

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without …

Jun 10, 2026
CVE-2025-8444
6.4 MEDIUM

The Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the …

Jun 10, 2026
CVE-2026-26239
8.1 HIGH

A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the …

Jun 10, 2026
CVE-2026-26237
7.5 HIGH

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized …

Jun 10, 2026
CVE-2026-24724
8.1 HIGH

An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the …

Jun 10, 2026
CVE-2026-24720
6.5 MEDIUM

An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, …

Jun 10, 2026
CVE-2026-24719
7.2 HIGH

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Jun 10, 2026
CVE-2026-24717
6.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Jun 10, 2026
CVE-2026-24716
7.2 HIGH

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Jun 10, 2026
CVE-2026-22899
6.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit …

Jun 10, 2026
CVE-2026-22893
7.2 HIGH

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Jun 10, 2026
CVE-2025-66281
7.2 HIGH

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch …

Jun 10, 2026
CVE-2025-66280
7.2 HIGH

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they …

Jun 10, 2026
CVE-2025-66279
7.2 HIGH

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Jun 10, 2026
CVE-2025-66273
7.2 HIGH

A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then …

Jun 10, 2026
CVE-2025-62851
4.4 MEDIUM

A path traversal vulnerability has been reported to affect License Center. If a local attacker gains an administrator account, they can then exploit the vulnerability …

Jun 10, 2026
CVE-2025-62850
7.2 HIGH

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can …

Jun 10, 2026
CVE-2025-66276
9.8 CRITICAL

QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250913 and later

Jun 10, 2026
CVE-2025-59382

QTS, QuTS hero, QuTScloud are not affected. We have already fixed the vulnerability in the following version:

Jun 10, 2026
CVE-2025-58468

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or …

Jun 10, 2026
CVE-2026-46532
4.6 MEDIUM

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid …

Jun 10, 2026
CVE-2026-45542
7.1 HIGH

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the …

Jun 10, 2026
CVE-2026-45541
7.5 HIGH

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket …

Jun 10, 2026
CVE-2026-45329
7.1 HIGH

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c validated only …

Jun 10, 2026
CVE-2026-45328
9.3 CRITICAL

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c …

Jun 10, 2026
CVE-2026-45160
6.5 MEDIUM

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the …

Jun 10, 2026
CVE-2026-46546

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially …

Jun 10, 2026
CVE-2026-44634

SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities in SimpleBLE. …

Jun 10, 2026
CVE-2026-53675
4.3 MEDIUM

BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend …

Jun 10, 2026
CVE-2026-53674
7.1 HIGH

BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a …

Jun 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.