CVE Database

46686+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-9104
6.4 MEDIUM

The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due …

May 22, 2026
CVE-2026-7509
6.4 MEDIUM

The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `the-subtitle` shortcode `before` and `after` attributes in all versions up …

May 22, 2026
CVE-2026-7249
4.3 MEDIUM

The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the `splw_update_block_options()` and `lwp_clean_weather_transients()` functions in …

May 22, 2026
CVE-2026-6864
6.1 MEDIUM

The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, …

May 22, 2026
CVE-2026-4070
4.3 MEDIUM

The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due …

May 22, 2026
CVE-2026-44409
5.7 MEDIUM

There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration of the access control mechanism, attackers can obtain information without authorization, …

May 22, 2026
CVE-2026-3481
6.1 MEDIUM

The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This …

May 22, 2026
CVE-2026-2518
4.3 MEDIUM

The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and activation due to missing capability checks on the 'ultp_install_callback' and 'ultp_activate_callback' functions …

May 22, 2026
CVE-2026-22678
5.4 MEDIUM

Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged …

May 21, 2026
CVE-2026-4843
4.3 MEDIUM

The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function …

May 21, 2026
CVE-2026-48249
5.9 MEDIUM

Open ISES Tickets before 3.44.2 disables TLS certificate verification in rm/incs/mobile_login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests …

May 21, 2026
CVE-2026-48248
5.9 MEDIUM

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/login.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests …

May 21, 2026
CVE-2026-48247
5.9 MEDIUM

Open ISES Tickets before 3.44.2 disables TLS certificate verification in incs/functions.inc.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests …

May 21, 2026
CVE-2026-48246
5.9 MEDIUM

Open ISES Tickets before 3.44.2 disables TLS certificate verification in ajax/reports.php by setting CURLOPT_SSL_VERIFYPEER to false (and not setting CURLOPT_SSL_VERIFYHOST) when issuing outbound HTTPS requests …

May 21, 2026
CVE-2026-48245
5.3 MEDIUM

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is committed to the public source repository. The key can …

May 21, 2026
CVE-2026-48244
5.3 MEDIUM

Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that is committed to the public source repository. The key can …

May 21, 2026
CVE-2026-48243
5.3 MEDIUM

Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php that is committed to the public source repository. Any actor with …

May 21, 2026
CVE-2026-48230
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ticketsmdb_import.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48229
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_i.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48228
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_w.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48227
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48226
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in os_watch.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48225
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in landb.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48224
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics214.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48223
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213rr.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48222
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics213.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48221
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205a.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48220
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics205.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48219
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in ics202.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48218
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in icons/buttons/landb.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48217
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in delete_module.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48216
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in db_loader.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48215
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-48214
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-39593
6.5 MEDIUM

Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects HAPPY: from n/a through 1.0.10.

May 21, 2026
CVE-2026-48213
5.4 MEDIUM

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized …

May 21, 2026
CVE-2026-36189
6.2 MEDIUM

Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrustify_d-0.82.0-132-bcc41cbdc and Fixed in commit 68e67b9a1435a1bb173b106fedb4a4f510972bdc allows a local attacker to cause a denial of service via the …

May 21, 2026
CVE-2026-1816
6.3 MEDIUM

Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force. This issue affects Mobile Application: from 1.6.2 …

May 21, 2026
CVE-2026-1815
5.7 MEDIUM

Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking. This issue affects Mobile Application: from 1.6.2 before 1.13.

May 21, 2026
CVE-2026-34926
6.7 MEDIUM KEV

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to …

May 21, 2026
CVE-2026-45254
6.5 MEDIUM

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was …

May 21, 2026
CVE-2026-45252
5.5 MEDIUM

When a fusefs file system implements extended attributes, the kernel may send a FUSE_LISTXATTR message to the userspace daemon to retrieve the list of extended …

May 21, 2026
CVE-2026-42396
4.9 MEDIUM

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

May 21, 2026
CVE-2026-42002
5.9 MEDIUM

Concurrency and locking defects in GSS-TSIG

May 21, 2026
CVE-2026-42000
6.8 MEDIUM

Insufficient Validation of Names During AXFR

May 21, 2026
CVE-2026-41999
4.8 MEDIUM

Incorrect Behaviour of Views with TCP PROXY Requests

May 21, 2026
CVE-2026-5434
5.9 MEDIUM

Honeywell Control Network Module (CNM) contains insertion of sensitive information into an unintended directory. An attacker could exploit this vulnerability through probing system files, potentially …

May 21, 2026
CVE-2026-27393
5.3 MEDIUM

Missing Authorization vulnerability in Tobias CF7 WOW Styler allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CF7 WOW Styler: from n/a through …

May 21, 2026
CVE-2026-27349
4.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data. This issue affects Mail …

May 21, 2026
CVE-2026-22880
6.1 MEDIUM

Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling …

May 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.