CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-105176
4.7 MEDIUM

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /Admin/edit_class.php. This manipulation of the argument ID …

Oct 5, 2026
CVE-2026-105292
5.9 MEDIUM

Chaterm before 0.12.1 contains a login cross-site request forgery vulnerability that allows remote attackers to inject login state by sending chaterm:// callbacks without OAuth state …

Oct 5, 2026
CVE-2026-105174
5.4 MEDIUM

A vulnerability has been found in Gerapy up to 0.9.13. This vulnerability affects the function project_create of the file gerapy/server/core/views.py of the component Project Management. …

Oct 5, 2026
CVE-2026-105171
6.3 MEDIUM

A security vulnerability has been detected in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. Affected by this vulnerability is an unknown functionality of the file admin/admin.php of the component …

Oct 5, 2026
CVE-2026-105168
6.3 MEDIUM

A vulnerability was identified in kishor-23 food-waste-management-system 411989e3ecb82895e53dca7865f72145f03d7d93/b3a70b2c492dc9904de5be1ad9389bd79b87f82c. This affects an unknown function of the file admin/admin.php of the component Order Assignment Block. The manipulation …

Oct 5, 2026
CVE-2026-105165
6.3 MEDIUM

A vulnerability has been found in devopspolis secrets-replicator up to 0.4.0. Impacted is the function process_single_secret of the file src/handler.py of the component AssumeRole Handler. …

Oct 4, 2026
CVE-2026-105163
5.3 MEDIUM

A vulnerability was detected in crossplane crossplane-runtime up to 2.2.2/2.3.2. This vulnerability affects the function Get of the file pkg/xpkg/client.go of the component ImageConfig. The …

Oct 4, 2026
CVE-2026-105161
5.3 MEDIUM

A flaw has been found in invariant-systems-ai aiir up to 1.7.0. The affected element is an unknown function of the component Policy Gate Handler. Executing …

Oct 4, 2026
CVE-2026-105224
5.4 MEDIUM

YesWiki before 4.6.7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched …

Oct 4, 2026
CVE-2026-104402
4.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data.This issue affects Mindio Magic MCP: from …

Oct 4, 2026
CVE-2026-105205
5.3 MEDIUM

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents …

Oct 4, 2026
CVE-2026-105157
4.3 MEDIUM

A security vulnerability has been detected in RainyGao DocSys up to 2.02.85. The affected element is the function DocController.doGetTmp of the file /Doc/doGetTmpFile.do of the …

Oct 4, 2026
CVE-2026-105146
4.7 MEDIUM

A vulnerability was found in Comsenz Discuz! X5.0-20260801/X5.0-20260820/X5.0-20260910. Affected by this issue is the function modmedalsubmit of the file upload/source/app/admin/child/medals/mod.php of the component Admin Medal …

Oct 4, 2026
CVE-2026-105145
5.3 MEDIUM

A vulnerability has been found in Weaviate Verba up to 2.1.3. Affected by this vulnerability is the function get_environment of the file goldenverba/components/util.py of the …

Oct 4, 2026
CVE-2026-105144
5.3 MEDIUM

A flaw has been found in Drogon up to 1.9.13-1/10.0-beta.3 on Windows. Affected is the function StaticFileRouter::route of the file lib/src/StaticFileRouter.cc of the component Static …

Oct 4, 2026
CVE-2026-105141
6.3 MEDIUM

A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affected element is the function get_user_id_by_email of the file cognee/modules/users/authentication/get_api_auth_backend.py of the …

Oct 4, 2026
CVE-2026-105137
5.0 MEDIUM

A vulnerability was found in Laradock up to 20.4. Impacted is an unknown function of the file workspace/Dockerfile of the component Build Process. The manipulation …

Oct 4, 2026
CVE-2026-97332
5.3 MEDIUM

The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies …

Oct 4, 2026
CVE-2026-86817
4.9 MEDIUM

The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing …

Oct 4, 2026
CVE-2026-17005
6.8 MEDIUM

The Horizontal scrolling announcements WordPress plugin through 2.6 does not sanitise and escape one of its announcement settings before outputting it into an attribute context …

Oct 4, 2026
CVE-2026-104118
5.3 MEDIUM

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated …

Oct 4, 2026
CVE-2026-105098
4.3 MEDIUM

A security flaw has been discovered in Omega Solution CoinEx Crypto 2025. Affected is an unknown function of the file /ticket/customer of the component Support …

Oct 4, 2026
CVE-2026-105097
4.3 MEDIUM

A vulnerability was identified in Omega Solution CoinEx Crypto 2025. This impacts an unknown function of the file /customer-currency/ of the component Customer Information API. …

Oct 4, 2026
CVE-2026-105131
5.4 MEDIUM

ezBookkeeping 1.2.0 before 2.0.1 contains a privilege escalation vulnerability that allows attackers holding an API token to obtain a full session token via /api/v1/tokens/refresh.json. Because …

Oct 4, 2026
CVE-2026-105096
6.3 MEDIUM

A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. …

Oct 4, 2026
CVE-2026-105129
6.5 MEDIUM

LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability that allows authenticated users with only settings.view permission to read stored secrets through the settings API. Attackers …

Oct 4, 2026
CVE-2026-105128
5.4 MEDIUM

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and …

Oct 4, 2026
CVE-2026-105127
5.3 MEDIUM

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can …

Oct 4, 2026
CVE-2026-105124
6.1 MEDIUM

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment …

Oct 4, 2026
CVE-2026-105122
5.4 MEDIUM

OpenAM before 16.1.3 contains a server-side request forgery vulnerability that allows attackers able to register or modify OAuth 2.0 clients to make OpenAM fetch internal …

Oct 3, 2026
CVE-2026-105121
4.9 MEDIUM

OpenAM before 16.1.3 contains an improper authorization vulnerability that allows delegated administrators to destroy sessions outside their realms because realm checks use the requester's realm. …

Oct 3, 2026
CVE-2026-105120
4.9 MEDIUM

OpenAM before 16.1.3 contains an authorization bypass vulnerability in the sessions REST endpoint query operation that allows realm administrators to list sessions of every realm. …

Oct 3, 2026
CVE-2026-105119
6.8 MEDIUM

OpenAM before 16.1.3 applies its OAuth2 Provider PKCE enforcement only to authorization requests whose response_type is exactly code, so codes issued through OpenID Connect hybrid …

Oct 3, 2026
CVE-2026-105118
4.7 MEDIUM

OpenAM before 16.1.3 contains an open redirect vulnerability that allows unauthenticated attackers to redirect users by supplying an unverified id_token_hint to the /oauth2/connect/endSession endpoint. Attackers …

Oct 3, 2026
CVE-2026-105117
6.1 MEDIUM

OpenAM before 16.1.3 contains an email content injection vulnerability that allows unauthenticated attackers to control notification email wording via the forgotPassword and register actions on …

Oct 3, 2026
CVE-2026-105116
6.1 MEDIUM

OpenAM before 16.1.3 contains a latent cross-site scripting defect that places the SAML message, relay state and target URL unencoded into the load-balancer cookie bounce …

Oct 3, 2026
CVE-2026-105114
6.1 MEDIUM

OpenAM before 16.1.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject script by supplying crafted parameters rendered unencoded on the OAuth2 …

Oct 3, 2026
CVE-2026-105113
6.5 MEDIUM

Nezha Dashboard from 1.8.0 before 2.3.13 contains an improper locking vulnerability where a non-deferred mutex unlock leaks on a nil-map panic path. Any authenticated non-admin …

Oct 3, 2026
CVE-2026-105112
5.3 MEDIUM

Nezha from 1.8.0 before 2.3.13 contains a lock-order inversion in UpdateGroup and DeleteGroup that allows authenticated non-admin users to deadlock the alerting subsystem. Attackers can …

Oct 3, 2026
CVE-2026-104983
6.3 MEDIUM

A vulnerability has been found in Linux Mint Xreader up to 4.6.9. Impacted is the function g_file_get_child of the file shell/ev-window.c of the component PDF …

Oct 3, 2026
CVE-2026-92767
6.4 MEDIUM

The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 …

Oct 3, 2026
CVE-2026-104982
4.3 MEDIUM

A flaw has been found in Linux Mint Xreader up to 4.6.5. This issue affects the function setup_document_content_list/g_strdup_printf of the file backend/epub/epub-document.c of the component …

Oct 3, 2026
CVE-2026-97343
4.3 MEDIUM

The Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Improper Authentication leading to Account Persistence in all versions …

Oct 3, 2026
CVE-2026-93896
6.1 MEDIUM

The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the …

Oct 3, 2026
CVE-2026-92974
6.1 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'thumb_url' parameter in all versions …

Oct 3, 2026
CVE-2026-15795
6.4 MEDIUM

The Responsive Plus – Elementor Templates & Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up …

Oct 3, 2026
CVE-2026-11601
5.3 MEDIUM

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Oct 3, 2026
CVE-2026-104313
6.1 MEDIUM

The WPC Estimated Delivery Date for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'rule_data' parameter in all versions up to, …

Oct 3, 2026
CVE-2026-103519
5.4 MEDIUM

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due …

Oct 3, 2026
CVE-2026-103421
5.4 MEDIUM

The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'REQUEST_URI (path segment after /android_json/search/)' parameter …

Oct 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.