CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78860
7.8 HIGH

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via the storage of information in plaintext

Oct 5, 2026
CVE-2026-105679
7.3 HIGH

Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from …

Oct 5, 2026
CVE-2026-105677
7.2 HIGH

Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to …

Oct 5, 2026
CVE-2026-105675
7.5 HIGH

Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret …

Oct 5, 2026
CVE-2026-105651
7.3 HIGH

Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external …

Oct 5, 2026
CVE-2026-105650
8.1 HIGH

Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored …

Oct 5, 2026
CVE-2026-105649
7.3 HIGH

Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored …

Oct 5, 2026
CVE-2026-105392
7.3 HIGH

A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component …

Oct 5, 2026
CVE-2026-103348
7.2 HIGH

Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.

Oct 5, 2026
CVE-2026-103066
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue …

Oct 5, 2026
CVE-2026-100511
8.8 HIGH

Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from …

Oct 5, 2026
CVE-2026-100506
7.2 HIGH

Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.

Oct 5, 2026
CVE-2026-97303
7.6 HIGH

Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch …

Oct 5, 2026
CVE-2026-58880
7.0 HIGH

In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of …

Oct 5, 2026
CVE-2026-58865
7.5 HIGH

In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial …

Oct 5, 2026
CVE-2026-58859
7.8 HIGH

In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no …

Oct 5, 2026
CVE-2026-58854
7.8 HIGH

In multiple locations, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution …

Oct 5, 2026
CVE-2026-58841
7.8 HIGH

In multiple functions of VirtualAudioControllerTest.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation …

Oct 5, 2026
CVE-2026-58835
8.8 HIGH

In cfg2prop of btif_storage.cc, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote code execution with no …

Oct 5, 2026
CVE-2026-58815
7.8 HIGH

In multiple locations, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege …

Oct 5, 2026
CVE-2026-55286
7.8 HIGH

In stpropnci_process of stpropnci.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of …

Oct 5, 2026
CVE-2026-55280
8.8 HIGH

In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution …

Oct 5, 2026
CVE-2026-55270
7.8 HIGH

In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with …

Oct 5, 2026
CVE-2026-55269
7.8 HIGH

In FilterCapturedPacket of snoop_logger.cc, there is a possible memory safety issue due to improper input validation. This could lead to local escalation of privilege with …

Oct 5, 2026
CVE-2026-55266
7.8 HIGH

In qsort of libufdt_sysdeps_vendor.c, there is a possible out-of-bounds write due to resource exhaustion. This could lead to local escalation of privilege with no additional …

Oct 5, 2026
CVE-2026-49937
7.8 HIGH

In multiple functions of MessageQueueBase.h, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation …

Oct 5, 2026
CVE-2026-49933
7.8 HIGH

In handle_le_monitor_device_event of msft.cc, there is a possible control-flow hijack in the privileged bluetooth process due to an uninitialized pointer dereference. This could lead to …

Oct 5, 2026
CVE-2026-49885
7.8 HIGH

In rw_t4t_update_file of rw_t4t.cc, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege with no …

Oct 5, 2026
CVE-2026-49880
7.8 HIGH

In multiple functions of nfa_nfcee_act.cc, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Oct 5, 2026
CVE-2026-49878
7.2 HIGH

In wpas_handle_robust_av_scs_recv_action of robust_av.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remote code execution …

Oct 5, 2026
CVE-2026-45524
8.8 HIGH

In isSystem of WifiPermissionsUtil.java, there is a possible sandbox escape due to a missing permission check. This could lead to local escalation of privilege with …

Oct 5, 2026
CVE-2026-28648
7.8 HIGH

In Settings, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution …

Oct 5, 2026
CVE-2026-28647
7.8 HIGH

In updateState of DeviceAdminAppsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of …

Oct 5, 2026
CVE-2026-28641
7.8 HIGH

In shouldDisableUninstallButton of ApplicationActionButtonsPreferenceController.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of …

Oct 5, 2026
CVE-2026-28640
7.8 HIGH

In checkCallerIsCertInstallerOrSelfInProfile of CredentialStorageActivity.java, there is a possible permission bypass due to improper input validation. This could lead to local escalation of privilege with no …

Oct 5, 2026
CVE-2026-28625
7.8 HIGH

In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege …

Oct 5, 2026
CVE-2026-105643
7.3 HIGH

Ghost is a Node.js content management system. From version 6.34.0 until 6.67.0, embed cards in the Ghost editor could bypass protections against stored cross-site scripting. …

Oct 5, 2026
CVE-2026-105642
8.8 HIGH

Ghost is a Node.js content management system. From 6.56.0 until 6.67.0, an image processing library bundled with Ghost contained a vulnerability in its SVG handling. …

Oct 5, 2026
CVE-2026-105635
7.4 HIGH

Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including …

Oct 5, 2026
CVE-2026-105634
8.1 HIGH

Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, …

Oct 5, 2026
CVE-2026-105387
7.3 HIGH

A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file cover.php of the component Patient …

Oct 5, 2026
CVE-2026-105386
7.3 HIGH

A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of …

Oct 5, 2026
CVE-2026-104714
8.8 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the …

Oct 5, 2026
CVE-2026-104712
7.5 HIGH

Asymmetric resource consumption (amplification) vulnerability in Apache Struts. When a request parameter is bound to an arbitrary-precision decimal (java.math.BigDecimal) property that is then rendered through …

Oct 5, 2026
CVE-2026-103349
7.2 HIGH

Deserialization of Untrusted Data vulnerability in Rymera Web Co Product Feed PRO for WooCommerce woo-product-feed-pro allows Object Injection.This issue affects Product Feed PRO for WooCommerce: …

Oct 5, 2026
CVE-2026-103334
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations restaurant-reservations allows Retrieve Embedded Sensitive Data.This issue affects …

Oct 5, 2026
CVE-2026-100515
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Photo Reviews for WooCommerce woo-photo-reviews allows Reflected XSS.This issue affects Photo Reviews …

Oct 5, 2026
CVE-2026-105633
7.1 HIGH

Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the …

Oct 5, 2026
CVE-2026-105631
7.5 HIGH

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's …

Oct 5, 2026
CVE-2026-105630
8.7 HIGH

Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a …

Oct 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.