CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-7726
6.5 MEDIUM

The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` …

Aug 5, 2026
CVE-2026-7441
6.4 MEDIUM

The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up …

Aug 5, 2026
CVE-2026-7105
4.3 MEDIUM

The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all …

Aug 5, 2026
CVE-2026-71212
4.4 MEDIUM

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional …

Aug 5, 2026
CVE-2026-71210
5.3 MEDIUM

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request …

Aug 5, 2026
CVE-2026-71208
6.5 MEDIUM

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed …

Aug 5, 2026
CVE-2026-71205
6.5 MEDIUM

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting …

Aug 5, 2026
CVE-2026-71204
6.2 MEDIUM

changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked …

Aug 5, 2026
CVE-2026-71203
5.3 MEDIUM

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get() …

Aug 5, 2026
CVE-2026-6972
6.4 MEDIUM

The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in all versions up …

Aug 5, 2026
CVE-2026-5651
4.9 MEDIUM

The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (askeet_execute_sql_query, askeet_export_all_results) in all versions up to, …

Aug 5, 2026
CVE-2026-5116
4.4 MEDIUM

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0.5. …

Aug 5, 2026
CVE-2026-5108
4.4 MEDIUM

The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_settings[offline_message_txt]` setting in all versions up to, and including, …

Aug 5, 2026
CVE-2026-55998
5.3 MEDIUM

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a cluster that has private registry secrets configured, …

Aug 5, 2026
CVE-2026-55996
4.3 MEDIUM

A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use …

Aug 5, 2026
CVE-2026-55747
6.8 MEDIUM

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a `_path(workdir, p)` helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded …

Aug 5, 2026
CVE-2026-17532
6.1 MEDIUM

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up to, and including, 2.29.15. This is …

Aug 5, 2026
CVE-2026-17505
6.1 MEDIUM

The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, …

Aug 5, 2026
CVE-2026-15281
6.5 MEDIUM

The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up …

Aug 5, 2026
CVE-2026-11977
6.5 MEDIUM

The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the …

Aug 5, 2026
CVE-2026-11969
4.9 MEDIUM

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 …

Aug 5, 2026
CVE-2026-11920
4.9 MEDIUM

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter …

Aug 5, 2026
CVE-2026-11454
6.5 MEDIUM

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Aug 5, 2026
CVE-2026-71201
5.0 MEDIUM

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by …

Aug 5, 2026
CVE-2026-68080
6.5 MEDIUM

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive …

Aug 5, 2026
CVE-2026-68078
6.5 MEDIUM

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and …

Aug 5, 2026
CVE-2026-67555
6.5 MEDIUM

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and …

Aug 5, 2026
CVE-2026-67554
6.5 MEDIUM

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial …

Aug 5, 2026
CVE-2026-66277
6.5 MEDIUM

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and …

Aug 5, 2026
CVE-2026-49004
6.5 MEDIUM

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with …

Aug 5, 2026
CVE-2026-17515
4.3 MEDIUM

The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of …

Aug 5, 2026
CVE-2026-16968
6.5 MEDIUM

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access …

Aug 5, 2026
CVE-2026-16942
5.4 MEDIUM

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to …

Aug 5, 2026
CVE-2026-16613
4.3 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, …

Aug 5, 2026
CVE-2026-16583
6.1 MEDIUM

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files …

Aug 5, 2026
CVE-2026-8790
6.1 MEDIUM

The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up …

Aug 5, 2026
CVE-2026-7753
6.5 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX …

Aug 5, 2026
CVE-2026-66839
6.7 MEDIUM

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to …

Aug 5, 2026
CVE-2026-66344
6.7 MEDIUM

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute …

Aug 5, 2026
CVE-2026-5062
4.9 MEDIUM

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' …

Aug 5, 2026
CVE-2026-18903
4.3 MEDIUM

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument …

Aug 5, 2026
CVE-2026-15941
6.5 MEDIUM

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler …

Aug 5, 2026
CVE-2026-11421
6.5 MEDIUM

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in …

Aug 5, 2026
CVE-2026-18896
6.3 MEDIUM

A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument …

Aug 5, 2026
CVE-2026-18856
4.7 MEDIUM

A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import …

Aug 5, 2026
CVE-2026-45705
5.3 MEDIUM

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs …

Aug 5, 2026
CVE-2026-18853
5.3 MEDIUM

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such …

Aug 5, 2026
CVE-2026-18103
4.9 MEDIUM

A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured …

Aug 5, 2026
CVE-2026-18819
4.3 MEDIUM

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack …

Aug 4, 2026
CVE-2026-18818
6.3 MEDIUM

A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket …

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.