CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-104388
5.3 MEDIUM

Missing Authorization vulnerability in Blubrry Podcasting PowerPress Podcasting powerpress allows Retrieve Embedded Sensitive Data.This issue affects PowerPress Podcasting: from n/a through 11.17.9.

Oct 5, 2026
CVE-2026-104386
6.5 MEDIUM

Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through 9.1.3.

Oct 5, 2026
CVE-2026-103351
5.3 MEDIUM

Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking …

Oct 5, 2026
CVE-2026-103084
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LeapWorx Premium Addons for Elementor premium-addons-for-elementor allows Stored XSS.This issue affects Premium Addons …

Oct 5, 2026
CVE-2026-103079
5.4 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: …

Oct 5, 2026
CVE-2026-103078
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: …

Oct 5, 2026
CVE-2026-102914
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from …

Oct 5, 2026
CVE-2026-102393
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Starter Templates astra-sites allows Stored XSS.This issue affects Starter Templates: from …

Oct 5, 2026
CVE-2026-105250
4.3 MEDIUM

A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA …

Oct 5, 2026
CVE-2026-105249
4.8 MEDIUM

A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. …

Oct 5, 2026
CVE-2026-105248
6.3 MEDIUM

A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File …

Oct 5, 2026
CVE-2026-19954
5.4 MEDIUM

Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois command-line tool that queries WHOIS for the wrong domain for unicode domain names. pwhois encodes each …

Oct 5, 2026
CVE-2026-100727
5.3 MEDIUM

An improper access control vulnerability exists in GROWI, which allow an unauthenticated attacker to read files contained in non-public pages of the affected product when …

Oct 5, 2026
CVE-2026-84169
5.3 MEDIUM

The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not verify that a payment-confirmation request actually belongs to the order and customer it …

Oct 5, 2026
CVE-2026-78371
5.9 MEDIUM

The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded …

Oct 5, 2026
CVE-2026-13607
5.9 MEDIUM

The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates …

Oct 5, 2026
CVE-2026-105306
6.5 MEDIUM

A flaw was found in the Dynamic Client Registration flow of the Keycloak identity and access management server. The issue occurs because the registration process …

Oct 5, 2026
CVE-2026-105302
5.7 MEDIUM

A flaw was found in the User Session Note mapper of the Keycloak identity and access management solution. The issue occurs because the mapper does …

Oct 5, 2026
CVE-2026-105301
4.0 MEDIUM

A flaw was found in the X.509 client-certificate authenticator of Keycloak, a solution for identity and access management. The issue occurs when the server is …

Oct 5, 2026
CVE-2026-105233
6.3 MEDIUM

A vulnerability has been found in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file login.php of the component Login Flow. Such manipulation …

Oct 5, 2026
CVE-2026-105226
4.7 MEDIUM

A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component …

Oct 5, 2026
CVE-2026-105225
4.3 MEDIUM

A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such …

Oct 5, 2026
CVE-2026-105187
6.3 MEDIUM

A vulnerability has been found in itsourcecode Online Admission System 1.0. Affected is an unknown function of the file /admin/key.php. The manipulation of the argument …

Oct 5, 2026
CVE-2026-105186
6.3 MEDIUM

A flaw has been found in itsourcecode Online Admission System 1.0. This impacts an unknown function of the file /new.php. Executing a manipulation of the …

Oct 5, 2026
CVE-2026-105181
6.3 MEDIUM

A vulnerability was identified in itsourcecode Online Admission System 1.0. This issue affects some unknown processing of the file register1.php. The manipulation of the argument …

Oct 5, 2026
CVE-2026-20589
6.7 MEDIUM

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious …

Oct 5, 2026
CVE-2026-20588
6.7 MEDIUM

In mtee, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a …

Oct 5, 2026
CVE-2026-20587
6.7 MEDIUM

In mtee, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor …

Oct 5, 2026
CVE-2026-20579
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious …

Oct 5, 2026
CVE-2026-20544
6.8 MEDIUM

In meta, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if …

Oct 5, 2026
CVE-2026-20543
5.5 MEDIUM

In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges …

Oct 5, 2026
CVE-2026-20542
6.7 MEDIUM

In apusys, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Oct 5, 2026
CVE-2026-20541
5.3 MEDIUM

In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if …

Oct 5, 2026
CVE-2026-20540
5.3 MEDIUM

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if …

Oct 5, 2026
CVE-2026-20539
5.3 MEDIUM

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if …

Oct 5, 2026
CVE-2026-20538
5.3 MEDIUM

In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if …

Oct 5, 2026
CVE-2026-20537
6.7 MEDIUM

In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Oct 5, 2026
CVE-2026-20536
6.7 MEDIUM

In aidl, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Oct 5, 2026
CVE-2026-20535
6.7 MEDIUM

In aidl, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a …

Oct 5, 2026
CVE-2026-20534
5.3 MEDIUM

In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if …

Oct 5, 2026
CVE-2026-20533
6.7 MEDIUM

In display, there is a possible escalation of privilege due to an integer overflow. This could lead to local escalation of privilege if a malicious …

Oct 5, 2026
CVE-2026-20532
6.2 MEDIUM

In apu, there is a possible application crash due to double free. This could lead to local denial of service with no additional execution privileges …

Oct 5, 2026
CVE-2026-20530
6.7 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Oct 5, 2026
CVE-2026-20529
6.7 MEDIUM

In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Oct 5, 2026
CVE-2026-20528
6.7 MEDIUM

In ccci, there is a possible out of bounds write and read due to a missing bounds check. This could lead to local information disclosure, …

Oct 5, 2026
CVE-2026-20527
5.3 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Oct 5, 2026
CVE-2026-20525
5.3 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has …

Oct 5, 2026
CVE-2026-105180
6.3 MEDIUM

A vulnerability was determined in Jeebase 0.0.1. This vulnerability affects the function updateUser of the file /user/update/info of the component UserService. Executing a manipulation of …

Oct 5, 2026
CVE-2026-105178
4.7 MEDIUM

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the …

Oct 5, 2026
CVE-2026-105177
4.7 MEDIUM

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug …

Oct 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.