CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55530
6.1 MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, ast_grep_rewrite lacks the @require_approval decorator used by sibling mutation tools. With dry_run=False, an agent-controlled call …

Aug 25, 2026
CVE-2026-55529
6.9 MEDIUM

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-controlled localhost.evil.example HTTP origin matches …

Aug 25, 2026
CVE-2026-79623
6.3 MEDIUM

A security vulnerability has been detected in FishCodeTech Muteki up to 0.2.5. The affected element is an unknown function of the file .claude/settings.json of the …

Aug 25, 2026
CVE-2026-79406
4.3 MEDIUM

A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the …

Aug 25, 2026
CVE-2026-78885
5.6 MEDIUM

A vulnerability was identified in liketrek TREK up to 3.0.22. The impacted element is the function findOrCreateUser of the file server/src/services/oidcService.ts of the component OIDC …

Aug 25, 2026
CVE-2026-78581
4.2 MEDIUM

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain …

Aug 25, 2026
CVE-2026-63074
5.9 MEDIUM

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they …

Aug 25, 2026
CVE-2026-79673
6.5 MEDIUM

Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write operations including password changes. An attacker with …

Aug 25, 2026
CVE-2026-79672
5.5 MEDIUM

Ech0 before 4.4.3 fails to enforce scope-based authorization on nine comment panel admin endpoints, allowing access tokens with minimal scopes to perform full comment moderation …

Aug 25, 2026
CVE-2026-79671
5.5 MEDIUM

Ech0 before 4.4.3 contains a server-side request forgery vulnerability in the validateWebhookURL function (webhook_setting_service.go), which only validates literal IP addresses via net.ParseIP() and fails to …

Aug 25, 2026
CVE-2026-79670
4.8 MEDIUM

Ech0 before 4.4.3 contains a stored cross-site scripting vulnerability in the file upload endpoint that validates Content-Type using only client-supplied headers without server-side inspection. Attackers …

Aug 25, 2026
CVE-2026-79669
4.3 MEDIUM

Ech0 before 4.4.3 lacks authorization checks on system log endpoints allowing any authenticated non-admin user to read and stream all server logs. Attackers can access …

Aug 25, 2026
CVE-2026-79668
5.3 MEDIUM

Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows unauthenticated attackers to increment engagement metrics without identity verification or …

Aug 25, 2026
CVE-2026-79666
6.5 MEDIUM

Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated user to access system logs. Attackers with valid user sessions …

Aug 25, 2026
CVE-2026-79663
4.8 MEDIUM

Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed where tag names and markdown content are rendered without HTML escaping. …

Aug 25, 2026
CVE-2026-79661
6.5 MEDIUM

Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or rate limiting. Unauthenticated attackers can increment the fav_count counter …

Aug 25, 2026
CVE-2026-79660
5.3 MEDIUM

Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON serialization tags on the Comment model. Unauthenticated attackers …

Aug 25, 2026
CVE-2026-78864
6.3 MEDIUM

A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey …

Aug 25, 2026
CVE-2026-78684
5.3 MEDIUM

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream …

Aug 25, 2026
CVE-2026-77824
4.9 MEDIUM

The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, …

Aug 25, 2026
CVE-2026-75908
4.3 MEDIUM

The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not …

Aug 25, 2026
CVE-2026-18547
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 25, 2026
CVE-2026-17587
5.3 MEDIUM

The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Aug 25, 2026
CVE-2026-79652
5.9 MEDIUM

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various …

Aug 25, 2026
CVE-2026-78863
6.3 MEDIUM

A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. …

Aug 25, 2026
CVE-2026-21754
5.4 MEDIUM

HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within …

Aug 25, 2026
CVE-2026-21753
4.2 MEDIUM

HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the …

Aug 25, 2026
CVE-2026-76128
6.4 MEDIUM

The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 …

Aug 25, 2026
CVE-2026-75038
6.1 MEDIUM

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.

Aug 25, 2026
CVE-2026-78701
6.5 MEDIUM

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By …

Aug 25, 2026
CVE-2026-78322
6.5 MEDIUM

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, …

Aug 25, 2026
CVE-2026-18512
6.4 MEDIUM

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Approved Comment Body Rendered in Translation …

Aug 25, 2026
CVE-2026-18100
6.4 MEDIUM

The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget …

Aug 25, 2026
CVE-2026-78656
6.3 MEDIUM

A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_del.php. The manipulation of the argument …

Aug 25, 2026
CVE-2026-78470
6.5 MEDIUM

The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping …

Aug 25, 2026
CVE-2026-78467
4.3 MEDIUM

The Fluent Support Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up …

Aug 25, 2026
CVE-2026-78466
4.3 MEDIUM

The Fluent Boards Pro plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.11 due to missing …

Aug 25, 2026
CVE-2026-13215
6.8 MEDIUM

The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a filesystem. ext2_verify_disk_superblock() in subsys/fs/ext2/ext2_impl.c checks the magic …

Aug 25, 2026
CVE-2026-12561
6.4 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_raw_html shortcode in all versions up to and including 5.4.5. This …

Aug 25, 2026
CVE-2026-76063
6.4 MEDIUM

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wfp_featured_video_url' parameter in all versions up to, …

Aug 25, 2026
CVE-2026-75930
4.3 MEDIUM

The FundEngine – Donation and Crowdfunding Platform plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.8.1. This is …

Aug 25, 2026
CVE-2026-19943
6.4 MEDIUM

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'titleTag' Block Attribute in all …

Aug 25, 2026
CVE-2026-17089
6.1 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions …

Aug 25, 2026
CVE-2026-14280
6.6 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Aug 25, 2026
CVE-2026-75982
4.4 MEDIUM

The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in versions up to, and including, 4.4.4 via the learnpress_create_page AJAX …

Aug 25, 2026
CVE-2026-75019
6.4 MEDIUM

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored …

Aug 25, 2026
CVE-2026-10627
5.3 MEDIUM

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. …

Aug 25, 2026
CVE-2025-9878
6.4 MEDIUM

The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ppwp' shortcode …

Aug 25, 2026
CVE-2026-78679
6.5 MEDIUM

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a …

Aug 25, 2026
CVE-2026-78678
6.5 MEDIUM

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files by …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.