CVE Database

52085+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-4986
5.3 MEDIUM

The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook …

Jun 9, 2026
CVE-2026-41539
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass …

Jun 9, 2026
CVE-2026-8977
6.4 MEDIUM

The WP GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ninja_gdpr_ajax_actions' AJAX action in versions up to, and including, …

Jun 9, 2026
CVE-2026-8940
4.3 MEDIUM

The WP Meta Sort Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.9. This is due …

Jun 9, 2026
CVE-2026-8910
6.1 MEDIUM

The WP Emoticon Rating plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to …

Jun 9, 2026
CVE-2026-8909
4.3 MEDIUM

The WpMobi plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.3. This is due to missing or …

Jun 9, 2026
CVE-2026-8907
6.1 MEDIUM

The WP-Ultimate-Map plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to missing nonce validation …

Jun 9, 2026
CVE-2026-8904
4.3 MEDIUM

The FastPicker, an order picker and order management system (oms) for WooCommerce on steroids plugin for WordPress is vulnerable to Cross-Site Request Forgery in all …

Jun 9, 2026
CVE-2026-8902
4.3 MEDIUM

The AJAX Report Comments plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to …

Jun 9, 2026
CVE-2026-8895
6.4 MEDIUM

The kk blog card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'blog-card' shortcode in all versions up to, and including, …

Jun 9, 2026
CVE-2026-8883
6.4 MEDIUM

The Global Body Mass Index Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gbmicalc' shortcode in versions up to, and including, …

Jun 9, 2026
CVE-2026-8882
6.4 MEDIUM

The WP ApplicantStack Jobs Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.1.1 …

Jun 9, 2026
CVE-2026-8880
6.4 MEDIUM

The RomanCart Ecommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blclass' attribute (and other attributes) of the romancart_button shortcode in versions …

Jun 9, 2026
CVE-2026-8841
6.4 MEDIUM

The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, and …

Jun 9, 2026
CVE-2026-8499
5.3 MEDIUM

The Helpfulcrowd Product Reviews plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in versions up to, and including, 1.2.9. This is …

Jun 9, 2026
CVE-2026-7662
6.4 MEDIUM

The ePaperFlip Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'publicationid' attribute of the `epaperflip_embed` shortcode in all versions up to, …

Jun 9, 2026
CVE-2026-41980
5.5 MEDIUM

Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 9, 2026
CVE-2026-41979
5.5 MEDIUM

Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confidentiality.

Jun 9, 2026
CVE-2026-41978
4.4 MEDIUM

Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 9, 2026
CVE-2026-41975
6.3 MEDIUM

Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

Jun 9, 2026
CVE-2026-41854
4.2 MEDIUM

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side …

Jun 9, 2026
CVE-2026-41853
5.3 MEDIUM

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; …

Jun 9, 2026
CVE-2026-41851
5.3 MEDIUM

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL …

Jun 9, 2026
CVE-2026-41847
4.8 MEDIUM

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

Jun 9, 2026
CVE-2026-41846
5.9 MEDIUM

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting …

Jun 9, 2026
CVE-2026-41844
4.2 MEDIUM

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to …

Jun 9, 2026
CVE-2026-41843
5.9 MEDIUM

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; …

Jun 9, 2026
CVE-2026-41841
5.9 MEDIUM

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; …

Jun 9, 2026
CVE-2026-41840
5.9 MEDIUM

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; …

Jun 9, 2026
CVE-2026-41839
4.2 MEDIUM

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID …

Jun 9, 2026
CVE-2026-41838
4.8 MEDIUM

IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules. Affected …

Jun 9, 2026
CVE-2026-41715
6.1 MEDIUM

In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this …

Jun 9, 2026
CVE-2026-41710
5.9 MEDIUM

An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the …

Jun 9, 2026
CVE-2026-11623
4.5 MEDIUM

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use …

Jun 9, 2026
CVE-2026-11603
6.1 MEDIUM

The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter in all versions up to, and including, …

Jun 9, 2026
CVE-2026-10738
6.4 MEDIUM

The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax) in all versions up to, and including, …

Jun 9, 2026
CVE-2026-10553
4.3 MEDIUM

The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to …

Jun 9, 2026
CVE-2026-10024
6.4 MEDIUM

The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute in all versions up to, and including, 1.0.0 …

Jun 9, 2026
CVE-2026-5714
6.4 MEDIUM

The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parameter in all versions up to, and including, 4.1.8 …

Jun 9, 2026
CVE-2026-11621
4.7 MEDIUM

A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /admin/dcat-api/editor-md/upload of the component User Setting Page. …

Jun 9, 2026
CVE-2026-11620
5.3 MEDIUM

A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation …

Jun 9, 2026
CVE-2026-11619
6.3 MEDIUM

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component …

Jun 9, 2026
CVE-2026-10862
6.4 MEDIUM

The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due …

Jun 9, 2026
CVE-2026-44757
4.7 MEDIUM

SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certain conditions, when accessed by a victim, the injected …

Jun 9, 2026
CVE-2026-44755
4.3 MEDIUM

SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by authenticated users, resulting in an email spoofing vulnerability.This vulnerability has …

Jun 9, 2026
CVE-2026-44754
6.6 MEDIUM

The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing caller identification of permitted SAP-internal applications and are …

Jun 9, 2026
CVE-2026-44750
4.3 MEDIUM

SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileged user to perform actions …

Jun 9, 2026
CVE-2026-44746
6.1 MEDIUM

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticated attacker could craft a URL that embeds a …

Jun 9, 2026
CVE-2026-44744
6.5 MEDIUM

SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be exploited by an authenticated attacker to potentially execute unauthorized database …

Jun 9, 2026
CVE-2026-24315
4.2 MEDIUM

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could …

Jun 9, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.