CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-20524
8.4 HIGH

In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution …

Oct 5, 2026
CVE-2026-20523
8.4 HIGH

In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 5, 2026
CVE-2026-20522
8.4 HIGH

In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 5, 2026
CVE-2026-20521
8.4 HIGH

In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 5, 2026
CVE-2026-20520
7.5 HIGH

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if …

Oct 5, 2026
CVE-2026-20519
7.5 HIGH

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if …

Oct 5, 2026
CVE-2026-105295
7.5 HIGH

GitAhead 2.5.0 through 2.7.1 contains an insecure update mechanism that installs downloaded updates without integrity or signature verification and permanently ignores TLS errors after one …

Oct 5, 2026
CVE-2026-105294
7.4 HIGH

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig …

Oct 5, 2026
CVE-2026-105293
8.1 HIGH

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory …

Oct 5, 2026
CVE-2026-105223
7.4 HIGH

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the …

Oct 5, 2026
CVE-2026-105175
7.3 HIGH

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. …

Oct 5, 2026
CVE-2026-105172
7.3 HIGH

A vulnerability was detected in itsourcecode Online Admission System 1.0. Affected by this issue is some unknown functionality of the file /login1.php. Performing a manipulation …

Oct 5, 2026
CVE-2026-105170
7.3 HIGH

A weakness has been identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected is an unknown function of the file admin/signup.php of the component Admin Signup. This manipulation …

Oct 5, 2026
CVE-2026-105169
7.3 HIGH

A security flaw has been discovered in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This impacts an unknown function of the file delivery/delivery.php of the component Take Order Handler. …

Oct 5, 2026
CVE-2026-105222
7.4 HIGH

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. …

Oct 4, 2026
CVE-2026-105221
7.4 HIGH

The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. …

Oct 4, 2026
CVE-2026-105220
7.8 HIGH

Twine 2 desktop through 2.12.0 contains a cross-site scripting vulnerability in importStories() that executes markup from imported story files in the editor window. Attackers can …

Oct 4, 2026
CVE-2026-105167
7.3 HIGH

A vulnerability was determined in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The impacted element is an unknown function of the file admin/donate.php. Executing a manipulation of the argument …

Oct 4, 2026
CVE-2026-105166
7.3 HIGH

A vulnerability was found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. The affected element is the function insert of the file fooddonateform.php of the component Food Donation Form. …

Oct 4, 2026
CVE-2026-105219
7.5 HIGH

Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers …

Oct 4, 2026
CVE-2026-105218
7.4 HIGH

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to …

Oct 4, 2026
CVE-2026-105216
7.4 HIGH

go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true …

Oct 4, 2026
CVE-2026-105089
8.7 HIGH

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 …

Oct 4, 2026
CVE-2026-105086
8.7 HIGH

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. …

Oct 4, 2026
CVE-2026-105213
8.2 HIGH

ZITADEL 4.x before 4.17.1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated …

Oct 4, 2026
CVE-2026-105212
7.5 HIGH

ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or …

Oct 4, 2026
CVE-2026-105211
8.1 HIGH

ZITADEL before 4.17.1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the …

Oct 4, 2026
CVE-2026-105210
8.2 HIGH

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers …

Oct 4, 2026
CVE-2026-105208
7.7 HIGH

ZITADEL 4.x before 4.17.3 and 3.x through 3.4.15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token …

Oct 4, 2026
CVE-2026-105158
7.3 HIGH

A vulnerability was detected in RainyGao DocSys up to 2.02.85. The impacted element is the function BaseController.createDBForMysql of the file BaseController.java of the component Database …

Oct 4, 2026
CVE-2026-105149
7.3 HIGH

A security flaw has been discovered in mooSocial up to 3.2.4. This issue affects some unknown processing of the file /stores/all-products. Performing a manipulation of …

Oct 4, 2026
CVE-2026-105148
7.3 HIGH

A vulnerability was identified in SciPhi-AI R2R up to 3.6.6. This vulnerability affects unknown code of the file py/shared/abstractions/llm.py of the component Retrieval Completion API …

Oct 4, 2026
CVE-2026-105147
7.3 HIGH

A vulnerability was determined in SciPhi-AI R2R up to 3.6.6. This affects an unknown part of the component JWT Secret Handler. This manipulation of the …

Oct 4, 2026
CVE-2026-97307
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in StylemixThemes Cost Calculator Builder cost-calculator-builder allows Retrieve Embedded Sensitive Data.This issue affects Cost Calculator Builder: from …

Oct 4, 2026
CVE-2026-97276
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a …

Oct 4, 2026
CVE-2026-103354
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This …

Oct 4, 2026
CVE-2026-103344
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected …

Oct 4, 2026
CVE-2026-103062
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs TranslatePress translatepress-multilingual allows Stored XSS.This issue affects TranslatePress: from n/a through 3.3.6.

Oct 4, 2026
CVE-2026-93549
8.8 HIGH

The CoCart WordPress plugin before 4.9.7 does not scope its REST API authentication filter to its own endpoints, which disables WordPress core's REST nonce protection …

Oct 4, 2026
CVE-2026-105133
7.3 HIGH

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a …

Oct 4, 2026
CVE-2026-88779
7.5 HIGH KEV

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and …

Oct 4, 2026
CVE-2026-105126
7.2 HIGH

LaraDashboard before 1.4.8 contains an improper privilege management vulnerability that allows authenticated Admin users to escalate to Superadmin by editing or renaming roles. Attackers with …

Oct 4, 2026
CVE-2026-105123
8.8 HIGH

W (vincent-peugnet/wcms) through 3.18.0 contains a remote code execution vulnerability that allows authenticated editors to write arbitrary files by abusing the unvalidated path in POST …

Oct 4, 2026
CVE-2026-96451
8.8 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.

Oct 3, 2026
CVE-2026-103342
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected …

Oct 3, 2026
CVE-2026-103065
8.2 HIGH

Improper Validation of Specified Quantity in Input vulnerability in Themeum Kirki kirki allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Kirki: from n/a …

Oct 3, 2026
CVE-2026-105115
8.6 HIGH

OpenAM before 16.1.3 contains an unauthenticated arbitrary class instantiation vulnerability in the legacy JAX-RPC SOAP interface that allows remote attackers to load classes without authentication. …

Oct 3, 2026
CVE-2026-97660
7.2 HIGH

The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all …

Oct 3, 2026
CVE-2026-96267
7.5 HIGH

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, …

Oct 3, 2026
CVE-2026-94505
8.1 HIGH

The Nelio Content – Editorial Calendar & Social Media Auto-Posting plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Oct 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.