CVE Database

32607+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9284
8.2 HIGH

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and …

May 23, 2026
CVE-2026-6898
8.8 HIGH

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all …

May 23, 2026
CVE-2026-6897
8.8 HIGH

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all …

May 23, 2026
CVE-2026-6895
8.8 HIGH

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including …

May 23, 2026
CVE-2026-6419
8.8 HIGH

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to …

May 23, 2026
CVE-2026-45659
8.8 HIGH

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

May 22, 2026
CVE-2026-35430
8.8 HIGH

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

May 22, 2026
CVE-2026-26147
7.7 HIGH

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

May 22, 2026
CVE-2026-23663
7.5 HIGH

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

May 22, 2026
CVE-2026-41147
8.7 HIGH

NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability caused by insufficient server-side input sanitization …

May 22, 2026
CVE-2026-41076
8.1 HIGH

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass …

May 22, 2026
CVE-2026-41075
8.8 HIGH

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An …

May 22, 2026
CVE-2026-41074
7.1 HIGH

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who …

May 22, 2026
CVE-2026-41071
8.1 HIGH

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box …

May 22, 2026
CVE-2026-5843
8.2 HIGH

The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and executes arbitrary Python files from model directories …

May 22, 2026
CVE-2026-5817
8.2 HIGH

The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loading model tokenizers, and runs without sandboxing. This causes transformers.AutoTokenizer.from_pretrained() to …

May 22, 2026
CVE-2026-9291
7.1 HIGH

Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remote authenticated user with S3 write access to …

May 22, 2026
CVE-2026-6406
8.8 HIGH

The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied …

May 22, 2026
CVE-2026-40172
8.1 HIGH

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on …

May 22, 2026
CVE-2026-39968
7.1 HIGH

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution and API Authorization Bypass") …

May 22, 2026
CVE-2026-46727
8.1 HIGH

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) …

May 22, 2026
CVE-2026-39965
7.7 HIGH

TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block …

May 22, 2026
CVE-2026-9255
7.8 HIGH

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, …

May 22, 2026
CVE-2026-37470
7.3 HIGH

An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers …

May 22, 2026
CVE-2026-36228
7.3 HIGH

Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality

May 22, 2026
CVE-2026-34207
7.6 HIGH

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked …

May 22, 2026
CVE-2026-28445
8.7 HIGH

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via …

May 22, 2026
CVE-2026-9047
7.6 HIGH

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to …

May 22, 2026
CVE-2026-7325
7.1 HIGH

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentication material associated with a stored PAM …

May 22, 2026
CVE-2026-9256
8.1 HIGH

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with …

May 22, 2026
CVE-2026-8992
8.8 HIGH

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

May 22, 2026
CVE-2025-45145
7.5 HIGH

Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via …

May 22, 2026
CVE-2026-9277
8.1 HIGH

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The `.op` field was backslash-escaped character by character using `/(.)/g`, …

May 22, 2026
CVE-2026-8671
7.5 HIGH

Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before …

May 22, 2026
CVE-2026-44417
7.5 HIGH

The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that another path in the code might lead …

May 22, 2026
CVE-2026-5740
7.5 HIGH

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which …

May 22, 2026
CVE-2026-9011
7.5 HIGH

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. …

May 22, 2026
CVE-2026-8679
7.5 HIGH

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() …

May 22, 2026
CVE-2026-9018
8.8 HIGH

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, …

May 22, 2026
CVE-2026-4834
7.5 HIGH

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This …

May 22, 2026
CVE-2026-46597
7.5 HIGH

An incorrectly placed cast from bytes to int allowed for server-side panic in the AES-GCM packet decoder for well-crafted inputs.

May 22, 2026
CVE-2026-39829
7.5 HIGH

The RSA and DSA public key parsers did not enforce size limits on key parameters. A crafted public key with an excessively large modulus or …

May 22, 2026
CVE-2026-34911
7.7 HIGH

A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access files …

May 22, 2026
CVE-2026-8434
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8433
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8432
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8427
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8416
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a …

May 21, 2026
CVE-2026-8415
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS …

May 21, 2026
CVE-2026-8414
8.8 HIGH

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS …

May 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.