CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78285
8.5 HIGH

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

Aug 27, 2026
CVE-2026-78283
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

Aug 27, 2026
CVE-2026-78281
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

Aug 27, 2026
CVE-2026-78276
7.2 HIGH

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

Aug 27, 2026
CVE-2026-78271
7.2 HIGH

Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

Aug 27, 2026
CVE-2026-78261
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

Aug 27, 2026
CVE-2026-78257
8.8 HIGH

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

Aug 27, 2026
CVE-2026-75020
8.1 HIGH

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry …

Aug 27, 2026
CVE-2026-75005
7.5 HIGH

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count …

Aug 27, 2026
CVE-2026-74848
7.5 HIGH

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on …

Aug 27, 2026
CVE-2026-32564
8.5 HIGH

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

Aug 27, 2026
CVE-2026-32550
8.5 HIGH

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

Aug 27, 2026
CVE-2026-27330
8.6 HIGH

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

Aug 27, 2026
CVE-2026-78333
8.8 HIGH

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its …

Aug 27, 2026
CVE-2026-78137
7.5 HIGH

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a …

Aug 27, 2026
CVE-2026-77018
8.8 HIGH

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently …

Aug 27, 2026
CVE-2026-77017
7.7 HIGH

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed …

Aug 27, 2026
CVE-2026-47893
7.5 HIGH

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 …

Aug 27, 2026
CVE-2026-47889
7.5 HIGH

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework …

Aug 27, 2026
CVE-2026-47888
7.5 HIGH

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 …

Aug 27, 2026
CVE-2026-47886
7.5 HIGH

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is …

Aug 27, 2026
CVE-2026-47885
7.5 HIGH

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 …

Aug 27, 2026
CVE-2026-47879
7.7 HIGH

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - …

Aug 27, 2026
CVE-2026-47877
8.2 HIGH

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6

Aug 27, 2026
CVE-2026-47849
7.1 HIGH

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 …

Aug 27, 2026
CVE-2026-19715
7.5 HIGH

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is …

Aug 27, 2026
CVE-2026-19223
7.2 HIGH

The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite …

Aug 27, 2026
CVE-2026-13415
7.2 HIGH

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the …

Aug 27, 2026
CVE-2026-81491
7.3 HIGH

A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead …

Aug 27, 2026
CVE-2026-81421
7.3 HIGH

A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the …

Aug 27, 2026
CVE-2026-47852
7.5 HIGH

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI …

Aug 27, 2026
CVE-2026-47851
7.5 HIGH

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI …

Aug 27, 2026
CVE-2026-81203
7.3 HIGH

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of …

Aug 26, 2026
CVE-2026-47666
7.6 HIGH

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font …

Aug 26, 2026
CVE-2026-47665
8.7 HIGH

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, …

Aug 26, 2026
CVE-2026-81202
7.3 HIGH

A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD …

Aug 26, 2026
CVE-2026-77611
7.1 HIGH

SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested …

Aug 26, 2026
CVE-2026-77368
7.6 HIGH

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a …

Aug 26, 2026
CVE-2026-77317
8.1 HIGH

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a …

Aug 26, 2026
CVE-2026-75333
7.5 HIGH

yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path …

Aug 26, 2026
CVE-2026-75328
7.5 HIGH

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

Aug 26, 2026
CVE-2026-61617
7.7 HIGH

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not …

Aug 26, 2026
CVE-2026-43621
8.1 HIGH

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to …

Aug 26, 2026
CVE-2026-75415
7.5 HIGH

AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing …

Aug 26, 2026
CVE-2026-75413
7.5 HIGH

DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any …

Aug 26, 2026
CVE-2026-61792
7.7 HIGH

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their …

Aug 26, 2026
CVE-2026-55228
8.1 HIGH

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the …

Aug 26, 2026
CVE-2025-61480
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP …

Aug 26, 2026
CVE-2025-61479
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC …

Aug 26, 2026
CVE-2025-61478
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.