CVE Database

52246+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10075
5.3 MEDIUM

DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path …

May 29, 2026
CVE-2026-10074
4.9 MEDIUM

DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.

May 29, 2026
CVE-2026-10061
6.3 MEDIUM

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in …

May 29, 2026
CVE-2026-10060
6.3 MEDIUM

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads …

May 29, 2026
CVE-2026-49324
4.6 MEDIUM

Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with …

May 29, 2026
CVE-2026-49323
4.3 MEDIUM

Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year …

May 29, 2026
CVE-2026-9811
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the project selector component of Mautic 7. When rendering selection menus for associating projects with system entities, …

May 29, 2026
CVE-2026-9557
6.4 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigger outbound HTTP …

May 29, 2026
CVE-2025-12714
5.3 MEDIUM

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

May 29, 2026
CVE-2026-9189
5.3 MEDIUM

The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all …

May 29, 2026
CVE-2026-10058
4.8 MEDIUM

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are …

May 29, 2026
CVE-2026-10057
4.8 MEDIUM

ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are …

May 29, 2026
CVE-2026-10052
4.1 MEDIUM

A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make …

May 29, 2026
CVE-2026-10039
4.9 MEDIUM

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, …

May 29, 2026
CVE-2026-9243
6.4 MEDIUM

The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions …

May 29, 2026
CVE-2026-49322
4.3 MEDIUM

Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with read …

May 29, 2026
CVE-2026-9714
6.4 MEDIUM

The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, …

May 29, 2026
CVE-2026-9493
6.5 MEDIUM

Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing authenticated remote attackers to modify the parameter of a specific …

May 29, 2026
CVE-2026-6324
4.8 MEDIUM

A flaw was found in libsoup. A remote attacker could exploit an unsigned to signed conversion error in the `soup_body_input_stream_read_chunked()` function by sending a malicious …

May 29, 2026
CVE-2026-6275
6.4 MEDIUM

The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This …

May 29, 2026
CVE-2025-14042
6.4 MEDIUM

The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Project Details' custom field in Portfolio Items in …

May 29, 2026
CVE-2026-2128
5.3 MEDIUM

The Breeze plugin for WordPress is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in all versions up to, and including, 2.5.2 This …

May 29, 2026
CVE-2026-8995
4.3 MEDIUM

The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including …

May 29, 2026
CVE-2026-7430
4.4 MEDIUM

The Post Snippets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.0.19. This is due to insufficient …

May 29, 2026
CVE-2026-6892
5.0 MEDIUM

Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may allow a local attacker with login privileges to exploit a …

May 29, 2026
CVE-2026-6891
5.0 MEDIUM

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login …

May 29, 2026
CVE-2026-9996
6.5 MEDIUM

Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process …

May 28, 2026
CVE-2026-9989
6.3 MEDIUM

Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium …

May 28, 2026
CVE-2026-9986
4.2 MEDIUM

Insufficient validation of untrusted input in OptimizationGuide in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to perform …

May 28, 2026
CVE-2026-9985
5.3 MEDIUM

Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process …

May 28, 2026
CVE-2026-9981
6.5 MEDIUM

Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted …

May 28, 2026
CVE-2026-9980
5.0 MEDIUM

Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass …

May 28, 2026
CVE-2026-9979
5.0 MEDIUM

Insufficient validation of untrusted input in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass …

May 28, 2026
CVE-2026-9971
5.4 MEDIUM

Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI …

May 28, 2026
CVE-2026-9955
4.3 MEDIUM

Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

May 28, 2026
CVE-2026-9953
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9943
4.3 MEDIUM

Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted …

May 28, 2026
CVE-2026-9942
5.0 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

May 28, 2026
CVE-2026-9935
4.3 MEDIUM

Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

May 28, 2026
CVE-2026-9930
4.3 MEDIUM

Out of bounds write in Dawn in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory …

May 28, 2026
CVE-2026-9929
4.3 MEDIUM

Inappropriate implementation in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

May 28, 2026
CVE-2026-9921
4.3 MEDIUM

Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin information via a crafted HTML page. …

May 28, 2026
CVE-2026-9919
4.3 MEDIUM

Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted …

May 28, 2026
CVE-2026-9917
6.5 MEDIUM

Uninitialized Use in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9913
4.3 MEDIUM

Inappropriate implementation in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

May 28, 2026
CVE-2026-9912
6.5 MEDIUM

Inappropriate implementation in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9911
4.3 MEDIUM

Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted …

May 28, 2026
CVE-2026-9908
6.5 MEDIUM

Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via …

May 28, 2026
CVE-2026-9907
4.3 MEDIUM

Out of bounds read in Dawn in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted …

May 28, 2026
CVE-2026-9903
5.0 MEDIUM

Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to …

May 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.