CVE Database

138188+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-40948
5.4 MEDIUM

The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not …

Apr 18, 2026
CVE-2026-2986
6.4 MEDIUM

The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to, and including, 4.2.1 due …

Apr 18, 2026
CVE-2026-2505
5.4 MEDIUM

The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1, via the 'z_taxonomy_image' shortcode. This is …

Apr 18, 2026
CVE-2026-0894
6.4 MEDIUM

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, …

Apr 18, 2026
CVE-2026-41254
4.0 MEDIUM

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.

Apr 18, 2026
CVE-2026-32690
3.7 LOW

Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as …

Apr 18, 2026
CVE-2026-32228
7.5 HIGH

UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 …

Apr 18, 2026
CVE-2026-30912
7.5 HIGH

In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing …

Apr 18, 2026
CVE-2026-30898
8.8 HIGH

An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used …

Apr 18, 2026
CVE-2026-25917
7.2 HIGH

Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary …

Apr 18, 2026
CVE-2026-41253
6.9 MEDIUM

In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a …

Apr 18, 2026
CVE-2026-6518
8.8 HIGH

The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all …

Apr 18, 2026
CVE-2026-6048
6.4 MEDIUM

The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions …

Apr 18, 2026
CVE-2026-4801
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up …

Apr 18, 2026
CVE-2026-40494
9.8 CRITICAL

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's …

Apr 18, 2026
CVE-2026-40493
9.8 CRITICAL

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec …

Apr 18, 2026
CVE-2026-40492
9.8 CRITICAL

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec …

Apr 18, 2026
CVE-2026-40491
6.5 MEDIUM

gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting …

Apr 18, 2026
CVE-2026-40490
6.8 MEDIUM

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of …

Apr 18, 2026
CVE-2026-40489

editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have a stack-based buffer overflow in …

Apr 18, 2026
CVE-2026-40487
8.9 HIGH

Postiz is an AI social media scheduling tool. Prior to version 2.21.6, a file upload validation bypass allows any authenticated user to upload arbitrary HTML, …

Apr 18, 2026
CVE-2026-35582
8.8 HIGH

Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file …

Apr 18, 2026
CVE-2026-1838
6.1 MEDIUM

The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to …

Apr 18, 2026
CVE-2026-1559
6.4 MEDIUM

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to …

Apr 18, 2026
CVE-2026-40572
9.0 CRITICAL

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode …

Apr 18, 2026
CVE-2026-40350
8.8 HIGH

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access …

Apr 18, 2026
CVE-2026-40317
9.3 CRITICAL

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry …

Apr 18, 2026
CVE-2026-35465
7.5 HIGH

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, …

Apr 18, 2026
CVE-2026-40593
4.8 MEDIUM

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value …

Apr 18, 2026
CVE-2026-40582

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's …

Apr 18, 2026
CVE-2026-40581
8.1 HIGH

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records …

Apr 18, 2026
CVE-2026-40485
5.3 MEDIUM

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on …

Apr 18, 2026
CVE-2026-40484
9.1 CRITICAL

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from …

Apr 18, 2026
CVE-2026-40483
5.4 MEDIUM

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes …

Apr 18, 2026
CVE-2026-40482

ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQL. This issue …

Apr 18, 2026
CVE-2026-40480

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorization …

Apr 18, 2026
CVE-2026-40349
8.8 HIGH

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate …

Apr 18, 2026
CVE-2026-40348
7.7 HIGH

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger …

Apr 18, 2026
CVE-2026-40347
5.3 MEDIUM

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large …

Apr 18, 2026
CVE-2026-40346
6.5 MEDIUM

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request …

Apr 18, 2026
CVE-2026-40341
3.5 LOW

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used …

Apr 18, 2026
CVE-2026-40340
6.1 MEDIUM

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulnerability in `ptp_unpack_OI()` in `camlibs/ptp2/ptp-pack.c` (lines 530–563). …

Apr 18, 2026
CVE-2026-40339
5.2 MEDIUM

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 842). The …

Apr 18, 2026
CVE-2026-40338
5.2 MEDIUM

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in …

Apr 18, 2026
CVE-2026-40337
5.1 MEDIUM

The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given task with one of the DEV or …

Apr 18, 2026
CVE-2026-40336
2.4 LOW

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (lines 884–885). When …

Apr 18, 2026
CVE-2026-40335
5.2 MEDIUM

libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `ptp_unpack_DPV()` in `camlibs/ptp2/ptp-pack.c` (lines 622–629). The …

Apr 18, 2026
CVE-2026-40334
3.5 LOW

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exists in ptp_unpack_Canon_FE() in camlibs/ptp2/ptp-pack.c (line …

Apr 18, 2026
CVE-2026-40333
6.1 MEDIUM

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2/ptp-pack.c accept a data pointer but no …

Apr 18, 2026
CVE-2026-40324
9.1 CRITICAL

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth …

Apr 18, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.