CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-17350
5.4 MEDIUM

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, …

Jul 31, 2026
CVE-2026-17348
6.5 MEDIUM

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, …

Jul 31, 2026
CVE-2026-10686
5.8 MEDIUM

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-route …

Jul 31, 2026
CVE-2025-62347
4.3 MEDIUM

HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an …

Jul 31, 2026
CVE-2026-67350
4.3 MEDIUM

Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious …

Jul 31, 2026
CVE-2026-28145
5.3 MEDIUM

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects MasterStudy LMS: from n/a through 3.7.39.

Jul 31, 2026
CVE-2026-28144
4.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Flipper Code WP Maps allows Retrieve Embedded Sensitive Data. This issue affects WP Maps: from n/a …

Jul 31, 2026
CVE-2026-64607
5.3 MEDIUM

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or …

Jul 31, 2026
CVE-2026-44615
6.5 MEDIUM

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could …

Jul 31, 2026
CVE-2026-17567
5.3 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Jul 31, 2026
CVE-2026-18437
5.3 MEDIUM

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the …

Jul 31, 2026
CVE-2026-18436
5.3 MEDIUM

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). …

Jul 31, 2026
CVE-2026-65311
5.3 MEDIUM

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target …

Jul 31, 2026
CVE-2026-18218
4.2 MEDIUM

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a specific application …

Jul 31, 2026
CVE-2026-18215
6.8 MEDIUM

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where …

Jul 31, 2026
CVE-2026-18214
6.8 MEDIUM

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was …

Jul 31, 2026
CVE-2026-18211
4.2 MEDIUM

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, …

Jul 31, 2026
CVE-2026-18208
6.5 MEDIUM

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to …

Jul 31, 2026
CVE-2026-18203
6.5 MEDIUM

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to …

Jul 31, 2026
CVE-2026-16105
4.9 MEDIUM

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly …

Jul 31, 2026
CVE-2026-8155
5.4 MEDIUM

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or …

Jul 31, 2026
CVE-2026-15209
6.5 MEDIUM

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can …

Jul 31, 2026
CVE-2026-14931
6.5 MEDIUM

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check …

Jul 31, 2026
CVE-2026-14929
4.3 MEDIUM

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and …

Jul 31, 2026
CVE-2026-14928
6.5 MEDIUM

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing …

Jul 31, 2026
CVE-2026-14922
6.1 MEDIUM

WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the …

Jul 31, 2026
CVE-2026-14921
6.1 MEDIUM

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(),

Jul 31, 2026
CVE-2026-14847
4.3 MEDIUM

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated …

Jul 31, 2026
CVE-2026-14845
6.1 MEDIUM

The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in …

Jul 31, 2026
CVE-2026-14843
5.3 MEDIUM

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated …

Jul 31, 2026
CVE-2026-14834
6.5 MEDIUM

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the …

Jul 31, 2026
CVE-2026-14833
6.8 MEDIUM

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption …

Jul 31, 2026
CVE-2026-14554
6.5 MEDIUM

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with …

Jul 31, 2026
CVE-2026-14317
5.3 MEDIUM

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part …

Jul 31, 2026
CVE-2026-12697
5.4 MEDIUM

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing …

Jul 31, 2026
CVE-2026-12376
4.3 MEDIUM

The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access …

Jul 31, 2026
CVE-2026-63220
4.8 MEDIUM

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an …

Jul 31, 2026
CVE-2026-62323
6.3 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does …

Jul 31, 2026
CVE-2026-55499
4.3 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent …

Jul 31, 2026
CVE-2026-55497
6.5 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do …

Jul 31, 2026
CVE-2026-55496
4.3 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at …

Jul 31, 2026
CVE-2026-55495
4.3 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than …

Jul 31, 2026
CVE-2026-43833
5.3 MEDIUM

Full details and mitigation steps are currently restricted and will be published at a later date.

Jul 31, 2026
CVE-2026-66720
6.5 MEDIUM

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame …

Jul 30, 2026
CVE-2026-66369
6.5 MEDIUM

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific …

Jul 30, 2026
CVE-2026-66364
6.5 MEDIUM

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. …

Jul 30, 2026
CVE-2026-66349
6.5 MEDIUM

The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER …

Jul 30, 2026
CVE-2026-65421
6.5 MEDIUM

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the …

Jul 30, 2026
CVE-2026-63550
6.5 MEDIUM

The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over …

Jul 30, 2026
CVE-2026-63362
5.9 MEDIUM

An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a …

Jul 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.