CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-104969
6.5 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, the cycle-issues endpoint accepts issue UUIDs in the request body without validating that they belong …

Oct 5, 2026
CVE-2026-104967
5.4 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them …

Oct 5, 2026
CVE-2026-104965
5.4 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong …

Oct 5, 2026
CVE-2026-104964
6.8 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, Plane's project update endpoint authorizes the caller against the workspace slug in the request URL …

Oct 5, 2026
CVE-2026-104963
4.3 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/cycles/ through WorkspaceCyclesEndpoint and GET /api/workspaces/{slug}/modules/ through WorkspaceModulesEndpoint return records from every project in …

Oct 5, 2026
CVE-2026-104962
6.5 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/v1/workspaces/{slug}/projects/{project_id}/members/ returns the complete project-member roster, including each member's email address, first and last …

Oct 5, 2026
CVE-2026-104961
5.4 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceOwnerPermission does not require is_active=True when checking whether a user is a workspace owner. A …

Oct 5, 2026
CVE-2026-104960
6.5 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to …

Oct 5, 2026
CVE-2026-104956
5.3 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by and sub_group_by query parameters and passes them without …

Oct 5, 2026
CVE-2026-104955
5.4 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, a Project Member with role 15 can send a PATCH request to the project-member update …

Oct 5, 2026
CVE-2026-104894
4.3 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, the modules endpoint accepts issue UUIDs in the URL path without validating that they belong …

Oct 5, 2026
CVE-2026-104893
5.4 MEDIUM

Plane is an open-source project management tool. Prior to 1.4.0, GET /api/users/api-tokens/ allows an authenticated user to retrieve API-token records, while PATCH /api/users/api-tokens/{token_id}/ allows the …

Oct 5, 2026
CVE-2026-88397
6.5 MEDIUM

ApiAdmin v.5.0 and before is vulnerable to SQL Injection in the user-list endpoint GET /admin/User/getUsers via the gid parameter.

Oct 5, 2026
CVE-2026-105397
5.4 MEDIUM

LearnPress plugin for WordPress through 4.4.9.1 contains a stored cross-site scripting vulnerability that allows authenticated instructors to inject scripts via quiz question hint and explanation …

Oct 5, 2026
CVE-2026-105329
6.3 MEDIUM

A vulnerability was determined in TallCMS up to 4.8.0. This affects an unknown function of the file packages/tallcms/cms/src/Filament/Pages/ThemeManager.php of the component PluginManager. Executing a manipulation …

Oct 5, 2026
CVE-2026-89039
6.5 MEDIUM

A caller who can invoke the convert_playwright_script prompt in mcp-k6 can pass a bare file path as the playwright_script argument and receive the contents of …

Oct 5, 2026
CVE-2026-105421
5.3 MEDIUM

Missing Authorization vulnerability in Kit Kit (formerly ConvertKit) for WooCommerce convertkit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kit (formerly ConvertKit) for …

Oct 5, 2026
CVE-2026-77804
6.6 MEDIUM

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception …

Oct 5, 2026
CVE-2026-77802
6.3 MEDIUM

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple …

Oct 5, 2026
CVE-2026-105315
4.7 MEDIUM

A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag …

Oct 5, 2026
CVE-2026-39783
4.3 MEDIUM

Missing Authorization vulnerability in WP SYNTEX Polylang polylang allows Retrieve Embedded Sensitive Data.This issue affects Polylang: from n/a through 3.8.7.

Oct 5, 2026
CVE-2026-105396
5.4 MEDIUM

Heym before v0.0.112 contains a token leakage vulnerability in build_public_base_url() that allows unauthenticated attackers to redirect HITL review links by spoofing Origin or X-Forwarded-Host headers. …

Oct 5, 2026
CVE-2026-105073
5.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Arraytics WP Event Solution wp-event-solution allows Retrieve Embedded Sensitive Data.This issue affects WP …

Oct 5, 2026
CVE-2026-103684
5.3 MEDIUM

Missing Authorization vulnerability in Arraytics WP Event Solution wp-event-solution allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Solution: from n/a through …

Oct 5, 2026
CVE-2026-94669
5.3 MEDIUM

Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent …

Oct 5, 2026
CVE-2026-39763
4.3 MEDIUM

Missing Authorization vulnerability in Deepak Anand WP Dummy Content Generator wp-dummy-content-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Dummy Content Generator: …

Oct 5, 2026
CVE-2026-105291
4.3 MEDIUM

A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The …

Oct 5, 2026
CVE-2026-105288
4.3 MEDIUM

A vulnerability has been found in feelec-yishu feelcrm-os 1.0.0. Affected by this vulnerability is the function IndexController::index of the file App/ThinkPHP/Common/functions.php of the component Crm …

Oct 5, 2026
CVE-2026-105287
6.3 MEDIUM

A flaw has been found in feelec-yishu feelcrm-os 1.0.0. Affected is an unknown function of the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php of the component getMemberByGroups Endpoint. This manipulation …

Oct 5, 2026
CVE-2026-105286
6.3 MEDIUM

A vulnerability was detected in Totolink A3002MU 1.0.0-B20230403.1455. This impacts the function sub_44B250 of the file /boafrm/formUploadFile of the component File Upload Handler. The manipulation …

Oct 5, 2026
CVE-2026-97071
5.3 MEDIUM

Incorrect Calculation vulnerability in VillaTheme CURCY woo-multi-currency allows Integer Attacks.This issue affects CURCY: from n/a through 2.2.17.

Oct 5, 2026
CVE-2026-39721
5.4 MEDIUM

Missing Authorization vulnerability in Brainstorm Force Starter Templates astra-sites allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Starter Templates: from n/a through 4.7.7.

Oct 5, 2026
CVE-2026-105263
4.7 MEDIUM

A security flaw has been discovered in Shaarli up to 0.16.3. The affected element is the function MetadataController of the file application/front/controller/admin/MetadataController.php of the component …

Oct 5, 2026
CVE-2026-105254
6.3 MEDIUM

A vulnerability was identified in itsourcecode Online Admission System 1.0. Impacted is an unknown function of the file /admin/schoolyear.php. Such manipulation of the argument sy …

Oct 5, 2026
CVE-2026-105251
6.3 MEDIUM

A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG …

Oct 5, 2026
CVE-2026-105069
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nikki Blight QR Redirector qr-redirector allows Stored XSS.This issue affects QR Redirector: from …

Oct 5, 2026
CVE-2026-105068
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through …

Oct 5, 2026
CVE-2026-105064
6.5 MEDIUM

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows …

Oct 5, 2026
CVE-2026-105062
4.3 MEDIUM

Missing Authorization vulnerability in Brandtoss WP Admin Audit wp-admin-audit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Admin Audit: from n/a through …

Oct 5, 2026
CVE-2026-105060
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a …

Oct 5, 2026
CVE-2026-105056
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in impleCode eCommerce Product Catalog ecommerce-product-catalog allows Stored XSS.This issue affects eCommerce Product Catalog: …

Oct 5, 2026
CVE-2026-105055
5.3 MEDIUM

Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0.

Oct 5, 2026
CVE-2026-104675
4.3 MEDIUM

Missing Authorization vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets: from n/a …

Oct 5, 2026
CVE-2026-104673
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows …

Oct 5, 2026
CVE-2026-104409
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue …

Oct 5, 2026
CVE-2026-104404
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP give allows Stored XSS.This issue affects GiveWP: from …

Oct 5, 2026
CVE-2026-104401
4.3 MEDIUM

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Retrieve Embedded Sensitive Data.This issue affects …

Oct 5, 2026
CVE-2026-104400
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a …

Oct 5, 2026
CVE-2026-104397
5.3 MEDIUM

Missing Authorization vulnerability in Jeroen Peters Name Directory name-directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Name Directory: from n/a through 1.34.2.

Oct 5, 2026
CVE-2026-104396
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory allows Stored XSS.This issue affects Name Directory: from …

Oct 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.