CVE Database

132006+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-84025
2.2 LOW

The BEAR WordPress plugin before 1.2.2 does not perform ownership checks on several handlers that return product data by a user-supplied identifier, allowing users who …

Sep 12, 2026
CVE-2026-84024
4.3 MEDIUM

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce before saving its meta field configuration, allowing an attacker to overwrite that configuration …

Sep 12, 2026
CVE-2026-84023
6.5 MEDIUM

The BEAR WordPress plugin before 1.2.2 does not verify a CSRF nonce or check user capabilities before updating taxonomy terms, allowing an attacker to modify …

Sep 12, 2026
CVE-2026-83532
6.8 MEDIUM

The Custom Menu Wizard Widget WordPress plugin through 3.3.1 does not sanitize and escape several shortcode attributes before rendering them into HTML, allowing users with …

Sep 12, 2026
CVE-2026-82851
2.7 LOW

The Masteriyo LMS WordPress plugin before 3.4.1 does not verify ownership of, or restrict the type of, the records a user requests for download, allowing …

Sep 12, 2026
CVE-2026-82847
6.8 MEDIUM

The Masteriyo LMS WordPress plugin before 3.4.1 does not sanitise and escape one of its course fields before outputting it back in the course editor, …

Sep 12, 2026
CVE-2026-82845
9.9 CRITICAL

The Masteriyo LMS WordPress plugin before 3.4.1 does not prevent user-supplied values held as metadata from being deserialized when they are read back, allowing users …

Sep 12, 2026
CVE-2026-81742
8.8 HIGH

The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and …

Sep 12, 2026
CVE-2026-81429
7.1 HIGH

The Export & Import WPBakery Page Builder WordPress plugin through 1.0.2 does not perform any CSRF check on its template-import feature and does not sanitise …

Sep 12, 2026
CVE-2026-81402
9.8 CRITICAL

The DS Ad Rotator WordPress plugin through 0.8 does not perform any capability check, nonce verification, or file-type validation on its image upload handler, allowing …

Sep 12, 2026
CVE-2026-81090
7.2 HIGH

The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing …

Sep 12, 2026
CVE-2026-80494
8.6 HIGH

The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a file-read function on a public …

Sep 12, 2026
CVE-2026-80491
8.6 HIGH

The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, …

Sep 12, 2026
CVE-2026-78152
5.3 MEDIUM

The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by …

Sep 12, 2026
CVE-2026-77753
5.5 MEDIUM

The Temporary Login Without Password WordPress plugin before 1.9.9 does not prevent a temporary user from creating an Application Password, and does not revoke one …

Sep 12, 2026
CVE-2026-77752
7.2 HIGH

The Temporary Login Without Password WordPress plugin before 1.9.9 does not verify that the user requesting a temporary login holds network super admin rights before …

Sep 12, 2026
CVE-2026-77705
7.2 HIGH

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.10 does not verify that the user editing a customer or employee record is entitled …

Sep 12, 2026
CVE-2026-77689
5.3 MEDIUM

The Booking for Appointments and Events Calendar WordPress plugin before 9.8.1 does not verify that a payment was actually taken before recording a booking as …

Sep 12, 2026
CVE-2026-77006
9.6 CRITICAL

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, …

Sep 12, 2026
CVE-2026-77005
9.6 CRITICAL

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability …

Sep 12, 2026
CVE-2026-75800
9.8 CRITICAL

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated …

Sep 12, 2026
CVE-2026-87719
9.9 CRITICAL

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain …

Sep 12, 2026
CVE-2026-85706
10.0 CRITICAL KEV

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain …

Sep 12, 2026
CVE-2026-90467
4.0 MEDIUM

aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command …

Sep 12, 2026
CVE-2026-89268
5.4 MEDIUM

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce …

Sep 12, 2026
CVE-2026-89267
4.3 MEDIUM

starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. …

Sep 12, 2026
CVE-2026-89266
8.2 HIGH

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft …

Sep 12, 2026
CVE-2026-90461
6.3 MEDIUM

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

Sep 11, 2026
CVE-2026-90460

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are …

Sep 11, 2026
CVE-2026-90457

The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash …

Sep 11, 2026
CVE-2026-90456

An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active …

Sep 11, 2026
CVE-2026-90455

A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into …

Sep 11, 2026
CVE-2026-90454

A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the …

Sep 11, 2026
CVE-2026-90453

A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's …

Sep 11, 2026
CVE-2026-90452

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An …

Sep 11, 2026
CVE-2026-90451

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies …

Sep 11, 2026
CVE-2026-90450

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting …

Sep 11, 2026
CVE-2026-90449

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the …

Sep 11, 2026
CVE-2026-90448

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods …

Sep 11, 2026
CVE-2026-90447

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than …

Sep 11, 2026
CVE-2026-90446

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and …

Sep 11, 2026
CVE-2026-90445

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended …

Sep 11, 2026
CVE-2026-90444

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using …

Sep 11, 2026
CVE-2026-90443

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require …

Sep 11, 2026
CVE-2026-54258
6.5 MEDIUM

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` …

Sep 11, 2026
CVE-2026-54248
6.5 MEDIUM

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw …

Sep 11, 2026
CVE-2026-54241
7.4 HIGH

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset …

Sep 11, 2026
CVE-2026-54240
7.4 HIGH

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a …

Sep 11, 2026
CVE-2026-50018
6.5 MEDIUM

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint …

Sep 11, 2026
CVE-2026-50013
7.5 HIGH

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the …

Sep 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.