CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-4512
3.5 LOW

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context …

Apr 23, 2026
CVE-2026-4106
5.3 MEDIUM

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and …

Apr 23, 2026
CVE-2026-41040
7.5 HIGH

GROWI provided by GROWI, Inc. is vulnerable to a regular expression denial of service (ReDoS) via a crafted input string.

Apr 23, 2026
CVE-2026-34488
7.3 HIGH

IP Setting Software contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code …

Apr 23, 2026
CVE-2025-10549
5.1 MEDIUM

EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially …

Apr 23, 2026
CVE-2026-41990
4.0 MEDIUM

Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.

Apr 23, 2026
CVE-2026-41989
6.7 MEDIUM

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

Apr 23, 2026
CVE-2026-41988
3.2 LOW

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID …

Apr 23, 2026
CVE-2026-41233
5.4 MEDIUM

Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation …

Apr 23, 2026
CVE-2026-41232
5.0 MEDIUM

Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong …

Apr 23, 2026
CVE-2026-40529
4.7 MEDIUM

CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with …

Apr 23, 2026
CVE-2026-41231
7.5 HIGH

Froxlor is open source server administration software. Prior to version 2.3.6, `DataDump.add()` constructs the export destination path from user-supplied input without passing the `$fixed_homedir` parameter …

Apr 23, 2026
CVE-2026-41230
8.5 HIGH

Froxlor is open source server administration software. Prior to version 2.3.6, `DomainZones::add()` accepts arbitrary DNS record types without a whitelist and does not sanitize newline …

Apr 23, 2026
CVE-2026-41229
9.1 CRITICAL

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When …

Apr 23, 2026
CVE-2026-41228
9.9 CRITICAL

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against …

Apr 23, 2026
CVE-2026-3361
6.4 MEDIUM

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and including, …

Apr 23, 2026
CVE-2026-3007
5.4 MEDIUM

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to …

Apr 23, 2026
CVE-2026-3844
9.8 CRITICAL

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions …

Apr 23, 2026
CVE-2026-2951
5.4 MEDIUM

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and …

Apr 23, 2026
CVE-2026-41679
10.0 CRITICAL

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated …

Apr 23, 2026
CVE-2026-41243
5.4 MEDIUM

OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the …

Apr 23, 2026
CVE-2026-41211
10.0 CRITICAL

Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly …

Apr 23, 2026
CVE-2026-41208
8.8 HIGH

Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Versions of @paperclipai/server prior to 2026.416.0 …

Apr 23, 2026
CVE-2026-41206
7.8 HIGH

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. The plugin security validator in PySpector uses AST-based static analysis …

Apr 23, 2026
CVE-2026-41200

STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a …

Apr 23, 2026
CVE-2026-41197

Noir is a Domain Specific Language for SNARK proving systems that is designed to use any ACIR compatible proving system, and Brillig is the bytecode …

Apr 23, 2026
CVE-2026-41196
10.0 CRITICAL

Luanti (formerly Minetest) is an open source voxel game-creation platform. Starting in version 5.0.0 and prior to version 5.15.2, a malicious mod can trivially escape …

Apr 23, 2026
CVE-2026-41182
5.3 MEDIUM

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python …

Apr 23, 2026
CVE-2026-41180
7.5 HIGH

PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates the mounted request path using …

Apr 23, 2026
CVE-2026-1923
6.4 MEDIUM

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, …

Apr 23, 2026
CVE-2026-6878
5.6 MEDIUM

A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. …

Apr 23, 2026
CVE-2026-6874
4.3 MEDIUM

A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing …

Apr 23, 2026
CVE-2026-5935
7.3 HIGH

IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated user to execute arbitrary commands with …

Apr 23, 2026
CVE-2026-5926
6.5 MEDIUM

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 …

Apr 23, 2026
CVE-2026-4919
4.8 MEDIUM

IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI …

Apr 23, 2026
CVE-2026-4918
5.5 MEDIUM

IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web …

Apr 23, 2026
CVE-2026-4917
4.9 MEDIUM

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request …

Apr 23, 2026
CVE-2026-41179
9.8 CRITICAL

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting in version 1.48.0 and prior to version …

Apr 23, 2026
CVE-2026-41176
9.8 CRITICAL

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: …

Apr 23, 2026
CVE-2026-40062
7.5 HIGH

A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the operating system.

Apr 23, 2026
CVE-2026-3621
7.5 HIGH

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnerable to identity spoofing under limited conditions when an application …

Apr 23, 2026
CVE-2026-32679
7.8 HIGH

The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic …

Apr 23, 2026
CVE-2026-29198
9.8 CRITICAL

In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover of the first user with …

Apr 23, 2026
CVE-2026-1726
4.8 MEDIUM

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1

Apr 23, 2026
CVE-2026-1352
6.5 MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause …

Apr 23, 2026
CVE-2026-1274
4.9 MEDIUM

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

Apr 23, 2026
CVE-2026-1272
2.7 LOW

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

Apr 23, 2026
CVE-2025-36074
5.5 MEDIUM

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A …

Apr 23, 2026
CVE-2026-4049

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 22, 2026
CVE-2026-41455
8.5 HIGH

WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the url schema field accepts any string without protocol restriction …

Apr 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.