CVE Database

132006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-91825

Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could …

Sep 15, 2026
CVE-2026-91782
3.3 LOW

A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation …

Sep 15, 2026
CVE-2026-91781
3.3 LOW

A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. …

Sep 15, 2026
CVE-2026-91780
3.3 LOW

A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null …

Sep 15, 2026
CVE-2026-91779
3.3 LOW

A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. …

Sep 15, 2026
CVE-2026-87730

Rejected reason: this is rejected

Sep 15, 2026
CVE-2026-80217
8.8 HIGH

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on …

Sep 15, 2026
CVE-2026-77853
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in …

Sep 15, 2026
CVE-2026-76159

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges …

Sep 15, 2026
CVE-2026-75092
7.3 HIGH

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: …

Sep 15, 2026
CVE-2026-91819

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field …

Sep 15, 2026
CVE-2026-91778

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). …

Sep 15, 2026
CVE-2026-91091
4.3 MEDIUM

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. …

Sep 15, 2026
CVE-2026-91090
3.9 LOW

A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer …

Sep 15, 2026
CVE-2026-91089
6.3 MEDIUM

A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. …

Sep 15, 2026
CVE-2026-91088
4.8 MEDIUM

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. …

Sep 15, 2026
CVE-2026-91087
7.3 HIGH

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing …

Sep 15, 2026
CVE-2026-91086
6.3 MEDIUM

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the …

Sep 15, 2026
CVE-2026-91005
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture …

Sep 15, 2026
CVE-2026-90711
9.1 CRITICAL

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 …

Sep 15, 2026
CVE-2026-89141
6.5 MEDIUM

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Sep 15, 2026
CVE-2026-75983
7.5 HIGH

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, …

Sep 15, 2026
CVE-2026-18063
6.4 MEDIUM

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due …

Sep 15, 2026
CVE-2026-15402
6.4 MEDIUM

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter …

Sep 15, 2026
CVE-2026-91004
7.3 HIGH

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation …

Sep 15, 2026
CVE-2026-91003
9.1 CRITICAL

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. …

Sep 15, 2026
CVE-2026-91002
5.3 MEDIUM

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist …

Sep 15, 2026
CVE-2026-91001
9.9 CRITICAL

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing …

Sep 15, 2026
CVE-2026-86701
2.5 LOW

Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device …

Sep 15, 2026
CVE-2026-81320
5.5 MEDIUM

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, …

Sep 15, 2026
CVE-2026-81303
6.3 MEDIUM

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into …

Sep 15, 2026
CVE-2026-18232
5.3 MEDIUM

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of …

Sep 15, 2026
CVE-2026-17495
5.9 MEDIUM

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to …

Sep 15, 2026
CVE-2026-16593
6.8 MEDIUM

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated …

Sep 15, 2026
CVE-2026-16592
2.7 LOW

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role …

Sep 15, 2026
CVE-2026-15758
5.3 MEDIUM

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Sep 15, 2026
CVE-2026-90881
5.3 MEDIUM

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. …

Sep 15, 2026
CVE-2026-90880
7.4 HIGH

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing …

Sep 15, 2026
CVE-2026-90879
7.3 HIGH

A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such …

Sep 15, 2026
CVE-2026-90878
4.3 MEDIUM

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. …

Sep 15, 2026
CVE-2026-90877
7.3 HIGH

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation …

Sep 15, 2026
CVE-2026-90876
7.3 HIGH

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The …

Sep 15, 2026
CVE-2026-90858
7.3 HIGH

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a …

Sep 15, 2026
CVE-2026-90857
6.3 MEDIUM

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile …

Sep 15, 2026
CVE-2026-90856
7.3 HIGH

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the …

Sep 15, 2026
CVE-2026-90855
7.3 HIGH

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the …

Sep 15, 2026
CVE-2026-90854
7.3 HIGH

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The …

Sep 15, 2026
CVE-2026-90852
7.3 HIGH

A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary …

Sep 15, 2026
CVE-2026-88262

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

Sep 15, 2026
CVE-2026-88261

Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.