CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-80230
7.5 HIGH

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning …

Sep 6, 2026
CVE-2026-80229
7.5 HIGH

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated …

Sep 6, 2026
CVE-2026-13608
7.4 HIGH

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker …

Sep 6, 2026
CVE-2026-19633
8.8 HIGH

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted …

Sep 6, 2026
CVE-2026-86259
7.5 HIGH

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider …

Sep 6, 2026
CVE-2026-86214
7.3 HIGH

A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. …

Sep 6, 2026
CVE-2026-86213
7.3 HIGH

A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of …

Sep 6, 2026
CVE-2026-86250
7.5 HIGH

h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can send a crafted …

Sep 6, 2026
CVE-2026-86242
8.1 HIGH

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled …

Sep 6, 2026
CVE-2022-51009
7.5 HIGH

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with …

Sep 6, 2026
CVE-2026-86211
7.3 HIGH

A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation …

Sep 6, 2026
CVE-2026-86210
7.3 HIGH

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Sep 6, 2026
CVE-2026-86209
7.3 HIGH

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of …

Sep 6, 2026
CVE-2026-86208
7.3 HIGH

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation …

Sep 6, 2026
CVE-2026-86180
7.3 HIGH

A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php …

Sep 6, 2026
CVE-2026-84219
7.5 HIGH

The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store …

Sep 6, 2026
CVE-2026-18480
8.8 HIGH

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, …

Sep 6, 2026
CVE-2026-86168
7.3 HIGH

A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation …

Sep 6, 2026
CVE-2026-86166
8.8 HIGH

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing …

Sep 6, 2026
CVE-2026-86162
7.3 HIGH

A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument …

Sep 6, 2026
CVE-2026-86161
7.3 HIGH

A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86160
7.3 HIGH

A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of …

Sep 6, 2026
CVE-2026-86159
7.3 HIGH

A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument …

Sep 6, 2026
CVE-2026-18056
7.5 HIGH

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is …

Sep 6, 2026
CVE-2026-67277
8.2 HIGH KEV

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 …

Sep 5, 2026
CVE-2026-0799
8.7 HIGH

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, …

Sep 5, 2026
CVE-2026-86188
7.2 HIGH

AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback …

Sep 5, 2026
CVE-2026-86185
8.0 HIGH

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position …

Sep 5, 2026
CVE-2025-9049
8.8 HIGH

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Sep 5, 2026
CVE-2026-86177
8.8 HIGH

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers …

Sep 5, 2026
CVE-2026-86173
7.5 HIGH

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled …

Sep 5, 2026
CVE-2026-86169
8.8 HIGH

Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security …

Sep 5, 2026
CVE-2026-86123
8.7 HIGH

SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified hosts. Attackers can connect to …

Sep 5, 2026
CVE-2026-86119
8.6 HIGH

Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGIN environment variable is unset. Attackers …

Sep 5, 2026
CVE-2026-86117
8.1 HIGH

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without …

Sep 5, 2026
CVE-2026-83625
7.2 HIGH

The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, …

Sep 5, 2026
CVE-2026-81543
8.8 HIGH

The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due …

Sep 5, 2026
CVE-2026-84935
8.0 HIGH

The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those …

Sep 5, 2026
CVE-2026-84934
8.0 HIGH

The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose …

Sep 5, 2026
CVE-2026-82304
8.6 HIGH

The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL …

Sep 5, 2026
CVE-2026-81404
7.1 HIGH

The IPGP Visitors Origin WordPress plugin before 1.6 does not sanitise or escape user input before reflecting it back in the HTTP response, allowing unauthenticated …

Sep 5, 2026
CVE-2026-78438
7.2 HIGH

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via LazyLoad Background Mutator in all versions up to, …

Sep 5, 2026
CVE-2026-77830
7.2 HIGH

The Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content aria-label Placeholder in all versions up …

Sep 5, 2026
CVE-2026-77826
8.8 HIGH

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, …

Sep 5, 2026
CVE-2026-19887
8.8 HIGH

The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input …

Sep 5, 2026
CVE-2026-19858
7.5 HIGH

The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rendering, allowing unauthenticated …

Sep 5, 2026
CVE-2026-19769
7.2 HIGH

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' …

Sep 5, 2026
CVE-2026-18406
7.2 HIGH

The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field …

Sep 5, 2026
CVE-2026-16649
7.2 HIGH

The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 …

Sep 5, 2026
CVE-2026-15984
7.2 HIGH

The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to …

Sep 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.