CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-19914
7.2 HIGH

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due …

Sep 1, 2026
CVE-2026-75921
7.2 HIGH

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to …

Sep 1, 2026
CVE-2026-19952
7.5 HIGH

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in …

Sep 1, 2026
CVE-2026-19806
8.8 HIGH

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator …

Sep 1, 2026
CVE-2026-19796
7.2 HIGH

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up …

Sep 1, 2026
CVE-2026-19573
7.2 HIGH

The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 …

Sep 1, 2026
CVE-2026-82957
7.3 HIGH

A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook …

Aug 31, 2026
CVE-2026-82922
7.3 HIGH

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of …

Aug 31, 2026
CVE-2026-82921
7.3 HIGH

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the …

Aug 31, 2026
CVE-2026-82882
8.8 HIGH

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated …

Aug 31, 2026
CVE-2026-82397
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. …

Aug 31, 2026
CVE-2026-82393
7.5 HIGH

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts …

Aug 31, 2026
CVE-2026-77348
8.2 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php …

Aug 31, 2026
CVE-2026-83596
8.8 HIGH

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

Aug 31, 2026
CVE-2026-82919
7.3 HIGH

A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component …

Aug 31, 2026
CVE-2026-82914
7.3 HIGH

A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact …

Aug 31, 2026
CVE-2026-82908
8.8 HIGH

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the …

Aug 31, 2026
CVE-2026-82392
7.1 HIGH

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name …

Aug 31, 2026
CVE-2026-82229
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.

Aug 31, 2026
CVE-2026-82228
8.1 HIGH

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

Aug 31, 2026
CVE-2026-82225
7.4 HIGH

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

Aug 31, 2026
CVE-2026-82224
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.

Aug 31, 2026
CVE-2026-82221
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

Aug 31, 2026
CVE-2026-81892
8.1 HIGH

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single …

Aug 31, 2026
CVE-2026-81891
8.1 HIGH

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the …

Aug 31, 2026
CVE-2026-81889
8.6 HIGH

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side …

Aug 31, 2026
CVE-2026-81768
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.

Aug 31, 2026
CVE-2026-81765
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.

Aug 31, 2026
CVE-2026-81764
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.

Aug 31, 2026
CVE-2026-81298
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.

Aug 31, 2026
CVE-2026-81297
7.5 HIGH

Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Aug 31, 2026
CVE-2026-81296
7.5 HIGH

Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Aug 31, 2026
CVE-2026-81291
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

Aug 31, 2026
CVE-2026-81290
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.

Aug 31, 2026
CVE-2026-81287
8.5 HIGH

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

Aug 31, 2026
CVE-2026-79407
7.5 HIGH

A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() …

Aug 31, 2026
CVE-2026-75458
8.1 HIGH

The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID …

Aug 31, 2026
CVE-2026-61641
8.1 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an …

Aug 31, 2026
CVE-2026-54598
7.5 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any …

Aug 31, 2026
CVE-2026-51735
7.5 HIGH

Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request …

Aug 31, 2026
CVE-2026-13732
7.8 HIGH

A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that …

Aug 31, 2026
CVE-2026-83497
8.8 HIGH

Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to …

Aug 31, 2026
CVE-2026-72001
8.1 HIGH

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the …

Aug 31, 2026
CVE-2026-53553
7.7 HIGH

Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File …

Aug 31, 2026
CVE-2026-82815
7.3 HIGH

A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This …

Aug 31, 2026
CVE-2026-79750
7.7 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, …

Aug 31, 2026
CVE-2026-79747
7.1 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, …

Aug 31, 2026
CVE-2026-79746
8.1 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, …

Aug 31, 2026
CVE-2026-79745
7.1 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, …

Aug 31, 2026
CVE-2026-79744
8.8 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.