CVE Database

132006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-90552
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist …

Sep 12, 2026
CVE-2026-90551
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query …

Sep 12, 2026
CVE-2026-90550
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint …

Sep 12, 2026
CVE-2026-90549
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. …

Sep 12, 2026
CVE-2026-90548
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve …

Sep 12, 2026
CVE-2026-90547
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected …

Sep 12, 2026
CVE-2026-90546
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted …

Sep 12, 2026
CVE-2026-90545
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted …

Sep 12, 2026
CVE-2026-90544
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts …

Sep 12, 2026
CVE-2026-90543
5.3 MEDIUM

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and …

Sep 12, 2026
CVE-2026-90542
5.4 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler …

Sep 12, 2026
CVE-2026-90541
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET …

Sep 12, 2026
CVE-2026-90540
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos …

Sep 12, 2026
CVE-2026-90539
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by …

Sep 12, 2026
CVE-2026-90538
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. …

Sep 12, 2026
CVE-2026-90537
8.2 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide …

Sep 12, 2026
CVE-2026-90536
5.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can …

Sep 12, 2026
CVE-2026-90535
7.5 HIGH

Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers …

Sep 12, 2026
CVE-2026-90534
6.5 MEDIUM

Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level …

Sep 12, 2026
CVE-2026-90533
6.5 MEDIUM

Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user …

Sep 12, 2026
CVE-2026-15451
8.8 HIGH

The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.39. This is due to a mass …

Sep 12, 2026
CVE-2026-10148
6.4 MEDIUM

The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Elementor widgets in versions up to and …

Sep 12, 2026
CVE-2026-90474
6.8 MEDIUM

MCPHub before 1.0.32 contains an authentication bypass vulnerability in its embedded OAuth 2.0 authorization server where client authentication is disabled by default and PKCE enforcement …

Sep 12, 2026
CVE-2026-90473
5.3 MEDIUM

msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count …

Sep 12, 2026
CVE-2026-90472
5.3 MEDIUM

msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deserializes arrays and maps without nesting depth limits. Attackers can craft payloads with …

Sep 12, 2026
CVE-2026-89172

Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: …

Sep 12, 2026
CVE-2026-85200
7.5 HIGH

The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_ajax_info_window_loader function. …

Sep 12, 2026
CVE-2026-85198
6.5 MEDIUM

The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path in …

Sep 12, 2026
CVE-2026-78175
8.8 HIGH

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Sep 12, 2026
CVE-2026-78159
9.8 CRITICAL

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. …

Sep 12, 2026
CVE-2026-78006
9.8 CRITICAL

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. …

Sep 12, 2026
CVE-2026-77161
6.5 MEDIUM

The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and …

Sep 12, 2026
CVE-2026-17585
5.3 MEDIUM

The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Sep 12, 2026
CVE-2026-16482
7.5 HIGH

The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'compare' parameter in all versions up …

Sep 12, 2026
CVE-2026-11355
5.3 MEDIUM

The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple …

Sep 12, 2026
CVE-2026-87919
4.9 MEDIUM

The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the …

Sep 12, 2026
CVE-2026-87918
5.3 MEDIUM

The WPBot WordPress plugin before 8.5.7 does not perform any authorization or nonce check on several AJAX actions that relay prompts to its configured AI …

Sep 12, 2026
CVE-2026-87916
5.3 MEDIUM

The WPBot WordPress plugin before 8.6.0 does not perform any capability or nonce check on the AJAX action that lists stored chat sessions, allowing unauthenticated …

Sep 12, 2026
CVE-2026-87894
5.3 MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.3 does not perform any authorization check on the endpoint that returns a booking's confirmation details, and each …

Sep 12, 2026
CVE-2026-87892
5.3 MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.0 does not verify the order total or the selected payment method against its own server-side pricing when …

Sep 12, 2026
CVE-2026-87891
6.5 MEDIUM

The Rox Appointment Booking WordPress plugin before 1.2.0 does not perform any capability or authorization check when saving its holiday schedule, allowing unauthenticated attackers to …

Sep 12, 2026
CVE-2026-87888
8.0 HIGH

The YayPricing WordPress plugin before 3.5.7 does not perform an authorization check on a REST route that saves its pricing rules, allowing users with the …

Sep 12, 2026
CVE-2026-87842
7.5 HIGH

The Zonify WordPress plugin before 1.0.5 does not perform any capability or authentication check before returning the site's stored account login token, allowing unauthenticated attackers …

Sep 12, 2026
CVE-2026-87797
4.3 MEDIUM

The Sprout Invoices WordPress plugin before 20.8.16 does not perform a capability or ownership check before allowing a private note to be overwritten through one …

Sep 12, 2026
CVE-2026-87759
8.8 HIGH

The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied …

Sep 12, 2026
CVE-2026-86790
6.8 MEDIUM

The WP Highlight Box WordPress plugin through 1.0 does not escape some shortcode attributes before outputting them in a page where the shortcode is embedded, …

Sep 12, 2026
CVE-2026-85681
9.8 CRITICAL

The WP Component WordPress plugin through 2.2.4 does not have any capability or nonce checks on one of the actions it makes available to unauthenticated …

Sep 12, 2026
CVE-2026-84171
9.8 CRITICAL

The WP images upload on piclect WordPress plugin through 1.0 does not validate the name or type of uploaded files before writing them to a …

Sep 12, 2026
CVE-2026-84099
8.1 HIGH

The wpstorecart WordPress plugin through 5.0.7 does not prevent direct, unauthenticated access to a bundled add-on that deserializes user-supplied input without restricting the permitted classes, …

Sep 12, 2026
CVE-2026-84047
8.6 HIGH

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated …

Sep 12, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.