CVE Database

113997+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-57830
9.1 CRITICAL

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Jul 13, 2026
CVE-2026-57829
6.1 MEDIUM

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS.

Jul 13, 2026
CVE-2026-4769
9.8 CRITICAL

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented …

Jul 13, 2026
CVE-2026-15544
8.8 HIGH

A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation …

Jul 13, 2026
CVE-2026-15543
8.8 HIGH

A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in …

Jul 13, 2026
CVE-2026-15542
7.3 HIGH

A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection …

Jul 13, 2026
CVE-2026-15541
7.3 HIGH

A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component …

Jul 13, 2026
CVE-2026-15540
4.3 MEDIUM

A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component …

Jul 13, 2026
CVE-2026-14165
7.5 HIGH

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users …

Jul 13, 2026
CVE-2026-15539
4.7 MEDIUM

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component …

Jul 13, 2026
CVE-2026-15538
6.3 MEDIUM

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the …

Jul 13, 2026
CVE-2026-15537
7.3 HIGH

A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of …

Jul 13, 2026
CVE-2026-15536
6.3 MEDIUM

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid …

Jul 13, 2026
CVE-2026-12582
8.6 HIGH

The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated …

Jul 13, 2026
CVE-2026-12397
4.3 MEDIUM

The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users …

Jul 13, 2026
CVE-2026-12396
5.4 MEDIUM

The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a …

Jul 13, 2026
CVE-2026-12275
7.1 HIGH

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it …

Jul 13, 2026
CVE-2026-12274
6.5 MEDIUM

The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in …

Jul 13, 2026
CVE-2026-12273
4.3 MEDIUM

The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and …

Jul 13, 2026
CVE-2026-12271
5.4 MEDIUM

The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level …

Jul 13, 2026
CVE-2026-12081
5.0 MEDIUM

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing an attacker-supplied form-field …

Jul 13, 2026
CVE-2026-11964
9.1 CRITICAL

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated …

Jul 13, 2026
CVE-2026-11963
8.1 HIGH

The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify …

Jul 13, 2026
CVE-2026-10551
6.1 MEDIUM

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement hash used during the HTML …

Jul 13, 2026
CVE-2026-15535
6.3 MEDIUM

A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component …

Jul 13, 2026
CVE-2026-15533
4.7 MEDIUM

A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a …

Jul 13, 2026
CVE-2026-15532
2.4 LOW

A vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation …

Jul 13, 2026
CVE-2026-15531
5.3 MEDIUM

A vulnerability has been found in yashbhalgat HashNeRF-pytorch up to 82885e698295982504eb6a26d060a6b2473e3706. Affected by this issue is the function torch.load of the file run_nerf.py of the …

Jul 13, 2026
CVE-2026-15530
5.3 MEDIUM

A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=index&v=upload of the component …

Jul 13, 2026
CVE-2026-9492
7.8 HIGH

The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can …

Jul 13, 2026
CVE-2026-7162
7.8 HIGH

Successful exploitation of the integer overflow vulnerability could allow an attacker to achieve system-level access to the affected software.

Jul 13, 2026
CVE-2026-15553
5.3 MEDIUM

Enterprise Cloud Database developed by Ragic has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload malicious files and make them available for …

Jul 13, 2026
CVE-2026-15552
6.1 MEDIUM

Enterprise Cloud Database developed by Ragic has a Stored Cross-Site Scripting vulnerability, allowing unauthenticated remote attackers to inject persistent JavaScript code executed in users' browsers …

Jul 13, 2026
CVE-2026-15529
6.3 MEDIUM

A vulnerability was detected in yzhao062 pyod 3.5.0/3.5.1/3.5.2. Affected is the function pyod.utils.persistence.load of the file pyod/utils/persistence.py. Performing a manipulation of the argument path results …

Jul 13, 2026
CVE-2026-15528
3.3 LOW

A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the …

Jul 13, 2026
CVE-2026-15527
5.3 MEDIUM

A vulnerability has been found in better-auth better-icons up to 1.0.5. This vulnerability affects unknown code of the component scan_project_icons/sync_icon. Such manipulation of the argument …

Jul 13, 2026
CVE-2026-15526
3.3 LOW

A flaw has been found in augmnt augments-mcp-server 7.1.0. This issue affects the function scanProjectDeps of the file src/tools/v4/scan-project-deps.ts of the component scan_project_deps. Executing a …

Jul 13, 2026
CVE-2026-15525
6.3 MEDIUM

A vulnerability was detected in kLOsk adloop up to 0.9.0. This vulnerability affects the function _validate_urls of the file src/adloop/ads/write.py. Performing a manipulation of the …

Jul 13, 2026
CVE-2026-15524
3.3 LOW

A security vulnerability has been detected in alioshr memory-bank-mcp up to 0.2.1/3.1. This affects an unknown part of the file list-project-files-validation-factory.ts. Such manipulation of the …

Jul 13, 2026
CVE-2026-15523
6.3 MEDIUM

A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. …

Jul 13, 2026
CVE-2026-15522
5.3 MEDIUM

A security flaw has been discovered in tugcantopaloglu godot-mcp 2.0.0. Affected by this vulnerability is the function validatePath of the file build/index.js of the component …

Jul 13, 2026
CVE-2026-15521
5.3 MEDIUM

A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. The manipulation …

Jul 13, 2026
CVE-2026-15520
5.3 MEDIUM

A vulnerability was determined in GNU LibreDWG 0.13.4-154-g0b573035. This impacts the function decompress_R2004_section of the file src/decode.c of the component R2004 Section Decompression. Executing a …

Jul 13, 2026
CVE-2026-15519
5.0 MEDIUM

A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing …

Jul 13, 2026
CVE-2026-15551
5.5 MEDIUM

Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects .

Jul 13, 2026
CVE-2026-15518
4.7 MEDIUM

A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryController::storeFile of the file src/Http/Controllers/Admin/FileLibraryController.php of …

Jul 13, 2026
CVE-2026-15517
7.3 HIGH

A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx. This manipulation of the argument …

Jul 13, 2026
CVE-2026-15516
5.6 MEDIUM

A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The …

Jul 13, 2026
CVE-2026-15515
7.0 HIGH

A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk …

Jul 13, 2026
CVE-2026-15514
7.3 HIGH

A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCService.query of the file /customizemt/xkq/rpc.jsp of the …

Jul 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.