CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-93889
7.2 HIGH

The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up …

Oct 3, 2026
CVE-2026-75028
7.5 HIGH

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to Local File Inclusion in all versions up …

Oct 3, 2026
CVE-2026-18443
8.8 HIGH

The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in …

Oct 3, 2026
CVE-2026-97341
7.2 HIGH

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, …

Oct 3, 2026
CVE-2026-97337
7.5 HIGH

The Simple Membership plugin for WordPress is vulnerable to unauthorized modification of data and sensitive information disclosure in versions up to, and including, 4.8.3 via …

Oct 3, 2026
CVE-2026-96650
7.2 HIGH

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'platform_user_photo' Custom Field in all versions up to, and including, 3.3.11 due …

Oct 3, 2026
CVE-2026-96575
7.2 HIGH

The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in …

Oct 3, 2026
CVE-2026-96564
7.2 HIGH

The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions …

Oct 3, 2026
CVE-2026-93430
7.2 HIGH

The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title' and 'url' Render Args in gdrts_live_handler AJAX in all versions …

Oct 3, 2026
CVE-2026-91078
8.2 HIGH

The TillKit WordPress plugin before 1.0.5 does not require the hard-coded, publicly known PIN of the privileged POS account it creates on activation to be …

Oct 3, 2026
CVE-2026-89236
8.6 HIGH

The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL …

Oct 3, 2026
CVE-2026-88783
8.8 HIGH

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the …

Oct 3, 2026
CVE-2026-87091
7.2 HIGH

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Parameters in all versions up to, and including, 2.12.2 due …

Oct 3, 2026
CVE-2026-103913
7.5 HIGH

The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the stored latitude/longitude coordinates of a listing in versions up to, and including, 2.8.186. …

Oct 3, 2026
CVE-2026-103514
7.5 HIGH

The WP 2FA WordPress plugin before 4.1.0 does not invalidate a time-based one-time passcode once it has been used, allowing an attacker who knows an …

Oct 3, 2026
CVE-2026-101928
7.2 HIGH

The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, …

Oct 3, 2026
CVE-2026-101923
8.1 HIGH

The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to …

Oct 3, 2026
CVE-2026-101161
7.5 HIGH

The WP Ultimate Review WordPress plugin before 2.4.4 does not prevent unauthenticated users from storing crafted review content that makes the reviewed page fail with …

Oct 3, 2026
CVE-2026-101160
7.5 HIGH

The WP Ultimate Review WordPress plugin before 2.4.4 does not validate that a submitted review rating is numeric before storing it and later using it …

Oct 3, 2026
CVE-2026-101159
7.5 HIGH

The WP Ultimate Review WordPress plugin before 2.4.4 does not properly sanitise and escape reviews submitted through its public review form, which is available to …

Oct 3, 2026
CVE-2026-97644
8.8 HIGH

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, …

Oct 3, 2026
CVE-2026-92977
7.2 HIGH

The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, …

Oct 3, 2026
CVE-2026-92536
8.8 HIGH

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information …

Oct 3, 2026
CVE-2026-96270
7.2 HIGH

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Oct 3, 2026
CVE-2026-93428
7.5 HIGH

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to authorization bypass in all …

Oct 3, 2026
CVE-2026-104478
7.1 HIGH

Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download …

Oct 3, 2026
CVE-2026-104433
7.5 HIGH

Mooncake transfer engine before 0.3.12 contains an out-of-bounds read vulnerability in the readString function of include/common.h that allows unauthenticated attackers to crash the service by …

Oct 3, 2026
CVE-2026-97363
7.5 HIGH

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service …

Oct 2, 2026
CVE-2026-97212
7.3 HIGH

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results …

Oct 2, 2026
CVE-2026-94593
7.8 HIGH

Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the …

Oct 2, 2026
CVE-2026-94592
8.4 HIGH

Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per …

Oct 2, 2026
CVE-2026-94591
8.4 HIGH

Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and …

Oct 2, 2026
CVE-2026-82044
7.7 HIGH

UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated …

Oct 2, 2026
CVE-2026-82039
8.8 HIGH

UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values …

Oct 2, 2026
CVE-2026-39718
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6.

Oct 2, 2026
CVE-2026-104991
7.1 HIGH

Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to …

Oct 2, 2026
CVE-2026-104988
8.1 HIGH

A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without …

Oct 2, 2026
CVE-2026-96940
8.8 HIGH

Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

Oct 2, 2026
CVE-2026-103958
7.6 HIGH

Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to …

Oct 2, 2026
CVE-2020-37278
7.5 HIGH

Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: …

Oct 2, 2026
CVE-2014-125130
7.5 HIGH

CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive …

Oct 2, 2026
CVE-2026-59265
8.8 HIGH

A code execution issue in the Java integration in Apache OpenOffice v4.1.16 and earlier allows a crafted untrusted document to trigger executing arbitrary (even remote) …

Oct 2, 2026
CVE-2026-104861
7.5 HIGH

probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /<[-_.:a-zA-Z0-9][^>]*>/, which repeatedly scans to …

Oct 2, 2026
CVE-2026-104851
8.8 HIGH

fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 until 2026.6.0, fsspec.implementations.reference.ReferenceFileSystem evaluates fields from Kerchunk reference JSON documents through unrestricted …

Oct 2, 2026
CVE-2026-67989
7.5 HIGH

crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x

Oct 2, 2026
CVE-2026-51917
7.3 HIGH

FinRobot v1.0.0 is vulnerable to Code Injection in CodingUtils.modify_code.

Oct 2, 2026
CVE-2026-51916
7.5 HIGH

TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without …

Oct 2, 2026
CVE-2026-51914
8.8 HIGH

TransformerOptimus SuperAGI v0.0.14 is vulnerable to Incorrect Access Control in the agent template controller. In affected source snapshots, save_agent_as_template and publish_template in superagi/controllers/agent_template.py accept caller-supplied …

Oct 2, 2026
CVE-2026-51907
8.1 HIGH

In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on …

Oct 2, 2026
CVE-2026-51901
8.1 HIGH

SuperAGI up to 0.0.14 is vulnerable to Incorrect Access Control. The agent execution controller endpoint /api/agentexecutions/schedule allows authenticated users from one organization to schedule existing …

Oct 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.