CVE Database

138081+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-1952
9.8 CRITICAL

Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.

Apr 24, 2026
CVE-2026-1951
9.8 CRITICAL

Delta Electronics AS320T has no checking of the length of the buffer with the directory name vulnerability.

Apr 24, 2026
CVE-2026-1950
9.8 CRITICAL

Delta Electronics AS320T has No checking of the length of the buffer with the file name vulnerability.

Apr 24, 2026
CVE-2026-6810
5.3 MEDIUM

The Booking Calendar Contact Form plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.2.63 via the …

Apr 24, 2026
CVE-2026-5428
6.4 MEDIUM

The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image captions in the Image Grid/Slider/Carousel widget in versions up to …

Apr 24, 2026
CVE-2026-5364
8.1 HIGH

The Drag and Drop File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in versions up to, and including, …

Apr 24, 2026
CVE-2026-5347
5.3 MEDIUM

The HM Books Gallery plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.8.0. This is due to the absence …

Apr 24, 2026
CVE-2026-1949
9.8 CRITICAL

Delta Electronics AS320T has incorrect calculation of the buffer size on the stack in the GET/PUT request handler of the web service.

Apr 24, 2026
CVE-2026-6947
7.5 HIGH

DWM-222W USB Wi-Fi Adapter developed by D-Link has a Brute-Force Protection Bypass vulnerability, allowing unauthenticated adjacent network attackers to bypass login attempt limits to perform …

Apr 24, 2026
CVE-2026-6393
4.3 MEDIUM

The BetterDocs plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 4.3.11. This is due to a missing capability check …

Apr 24, 2026
CVE-2026-5488
5.3 MEDIUM

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is …

Apr 24, 2026
CVE-2026-41485
7.7 HIGH

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` …

Apr 24, 2026
CVE-2026-41430
6.1 MEDIUM

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). Redirect parameter on login page is vulnerable to reflected …

Apr 24, 2026
CVE-2026-41324
7.5 HIGH

basic-ftp is an FTP client for Node.js. Versions prior to 5.3.0 are vulnerable to denial of service through unbounded memory growth while processing directory listings …

Apr 24, 2026
CVE-2026-41323
8.1 HIGH

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.18.0-rc1, 1.17.2-rc1, and 1.16.4, Kyverno's apiCall feature in ClusterPolicy automatically …

Apr 24, 2026
CVE-2026-41319
6.5 MEDIUM

MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allows a Man-in-the-Middle …

Apr 24, 2026
CVE-2026-41318
5.4 MEDIUM

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's …

Apr 24, 2026
CVE-2026-41068
7.7 HIGH

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by …

Apr 24, 2026
CVE-2026-2028
5.3 MEDIUM

The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file ownership validation on the 'maxi_remove_custom_image_size' AJAX action in …

Apr 24, 2026
CVE-2026-41317
7.5 HIGH

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS).`press.api.account.create_api_secret` is prone to CSRF-like exploits. This endpoint writes to …

Apr 24, 2026
CVE-2026-41316
8.1 HIGH

ERB is a templating system for Ruby. Ruby 2.7.0 (before ERB 2.2.0 was published on rubygems.org) introduced an `@_init` instance variable guard in `ERB#result` and …

Apr 24, 2026
CVE-2026-41309
8.2 HIGH

Open Source Social Network (OSSN) is open-source social networking software developed in PHP. Versions prior to 9.0 are vulnerable to resource exhaustion. An attacker can …

Apr 24, 2026
CVE-2026-41305
6.1 MEDIUM

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions …

Apr 24, 2026
CVE-2026-40254
4.2 MEDIUM

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The …

Apr 24, 2026
CVE-2026-33318
8.8 HIGH

Actual is a local-first personal finance tool. Prior to version 26.4.0, any authenticated user (including `BASIC` role) can escalate to `ADMIN` on servers migrated from …

Apr 24, 2026
CVE-2026-33317
8.7 HIGH

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. In …

Apr 24, 2026
CVE-2026-33208
8.8 HIGH

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the /config/ < service > /find-in-config endpoint in …

Apr 24, 2026
CVE-2026-33078
9.8 CRITICAL

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability in the haproxy_section_save …

Apr 24, 2026
CVE-2026-33077
7.5 HIGH

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has …

Apr 24, 2026
CVE-2026-33076
9.8 CRITICAL

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could …

Apr 24, 2026
CVE-2026-32952
5.3 MEDIUM

go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out …

Apr 24, 2026
CVE-2026-41325
8.8 HIGH

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the …

Apr 24, 2026
CVE-2026-40099
6.5 MEDIUM

Kirby is an open-source content management system. Kirby's user permissions control which user role is allowed to perform specific actions to content models in the …

Apr 24, 2026
CVE-2026-34587
8.1 HIGH

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, Kirby's user permissions control which user role is allowed to perform specific …

Apr 24, 2026
CVE-2026-32870
7.5 HIGH

Kirby is an open-source content management system. Kirby's `Xml::value()` method has special handling for `<![CDATA[ ]]>` blocks. If the input value is already valid `CDATA`, …

Apr 24, 2026
CVE-2026-31956
4.3 MEDIUM

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to version 4.4.1, any authenticated …

Apr 24, 2026
CVE-2026-31955
4.9 MEDIUM

Xibo is an open source digital signage platform with a web content management system and Windows display player software. An authenticated Server-Side Request Forgery (SSRF) …

Apr 24, 2026
CVE-2026-31953
6.4 MEDIUM

Xibo is an open source digital signage platform with a web content management system and Windows display player software. A stored Cross-Site Scripting (XSS) vulnerability …

Apr 24, 2026
CVE-2026-40630
9.8 CRITICAL

A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network …

Apr 24, 2026
CVE-2026-40623
8.1 HIGH

A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due …

Apr 24, 2026
CVE-2026-40620
9.8 CRITICAL

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive …

Apr 24, 2026
CVE-2026-40431
5.3 MEDIUM

A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication …

Apr 24, 2026
CVE-2026-39462
8.1 HIGH

A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on …

Apr 24, 2026
CVE-2026-35503
9.8 CRITICAL

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed …

Apr 24, 2026
CVE-2026-35064
7.5 HIGH

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and …

Apr 24, 2026
CVE-2026-31952
7.6 HIGH

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Versions 1.7 through 4.4.0 have an …

Apr 24, 2026
CVE-2026-29197
4.3 MEDIUM

In versions <8.4.0, <8.3.2, <8.2.2, <8.1.3, <8.0.4, <7.13.6, <7.12.7, <7.11.7, and <7.10.10, the endpoints /api/apps/logs and /api/apps/:id/logs have a typo in the required permission check, …

Apr 24, 2026
CVE-2026-29051
4.4 MEDIUM

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, `melange lint --persist-lint-results` (opt-in flag, also …

Apr 24, 2026
CVE-2026-29050
6.1 MEDIUM

melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can influence a …

Apr 24, 2026
CVE-2026-27843
9.1 CRITICAL

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying …

Apr 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.