CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63317
5.6 MEDIUM

Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code …

Jul 24, 2026
CVE-2026-56392

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. …

Jul 24, 2026
CVE-2026-56391

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() …

Jul 24, 2026
CVE-2026-49745
7.8 HIGH

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the …

Jul 24, 2026
CVE-2026-49744
7.8 HIGH

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the …

Jul 24, 2026
CVE-2026-49743
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading …

Jul 24, 2026
CVE-2026-24727

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote …

Jul 24, 2026
CVE-2026-15821
6.4 MEDIUM

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …

Jul 24, 2026
CVE-2026-15739
6.4 MEDIUM

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and …

Jul 24, 2026
CVE-2026-15704
9.8 CRITICAL

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between …

Jul 24, 2026
CVE-2026-15346
6.1 MEDIUM

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, …

Jul 24, 2026
CVE-2026-12702

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

Jul 24, 2026
CVE-2026-16910
5.5 MEDIUM

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs without SSRF validation, allowing …

Jul 24, 2026
CVE-2026-16519
7.3 HIGH

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe …

Jul 24, 2026
CVE-2026-15755
6.4 MEDIUM

The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, …

Jul 24, 2026
CVE-2026-15665
6.4 MEDIUM

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all …

Jul 24, 2026
CVE-2026-15653
6.4 MEDIUM

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backend-title' parameter in …

Jul 24, 2026
CVE-2026-15648
6.4 MEDIUM

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 …

Jul 24, 2026
CVE-2026-15464
6.4 MEDIUM

The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to, and including, 2.3.2 …

Jul 24, 2026
CVE-2026-15334
6.4 MEDIUM

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored …

Jul 24, 2026
CVE-2026-15333
6.4 MEDIUM

The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored …

Jul 24, 2026
CVE-2026-12654
5.3 MEDIUM

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. This is due …

Jul 24, 2026
CVE-2026-14603
7.5 HIGH

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of …

Jul 24, 2026
CVE-2026-14172
7.8 HIGH

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code …

Jul 24, 2026
CVE-2026-12981
7.5 HIGH

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password …

Jul 24, 2026
CVE-2026-12877
9.1 CRITICAL

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a …

Jul 24, 2026
CVE-2026-12690
3.8 LOW

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform a capability check on its license management actions, relying only on a nonce that is exposed …

Jul 24, 2026
CVE-2026-12689
5.4 MEDIUM

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions, allowing authenticated users with …

Jul 24, 2026
CVE-2026-12688
6.5 MEDIUM

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthenticated attackers to forge a payment notification …

Jul 24, 2026
CVE-2026-12497
7.5 HIGH

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role …

Jul 24, 2026
CVE-2026-16870
8.8 HIGH

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file …

Jul 24, 2026
CVE-2026-66141
7.4 HIGH

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

Jul 24, 2026
CVE-2026-66140
8.4 HIGH

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

Jul 24, 2026
CVE-2026-66139
4.8 MEDIUM

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

Jul 24, 2026
CVE-2026-66138
7.2 HIGH

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a …

Jul 24, 2026
CVE-2026-54422
5.5 MEDIUM

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download …

Jul 24, 2026
CVE-2026-6454
6.4 MEDIUM

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to insufficient …

Jul 24, 2026
CVE-2026-15420
4.3 MEDIUM

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, …

Jul 24, 2026
CVE-2026-15100
6.4 MEDIUM

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, …

Jul 24, 2026
CVE-2026-13464
5.3 MEDIUM

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Jul 24, 2026
CVE-2026-12736
8.0 HIGH

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST …

Jul 24, 2026
CVE-2026-11922
6.5 MEDIUM

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the …

Jul 24, 2026
CVE-2026-11354
5.3 MEDIUM

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This …

Jul 24, 2026
CVE-2025-9205
6.4 MEDIUM

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficient input …

Jul 24, 2026
CVE-2026-62825
10.0 CRITICAL

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Jul 24, 2026
CVE-2026-58275
10.0 CRITICAL

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Jul 24, 2026
CVE-2026-56191
10.0 CRITICAL

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

Jul 24, 2026
CVE-2026-56167
8.5 HIGH

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

Jul 24, 2026
CVE-2026-56165
9.8 CRITICAL

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

Jul 24, 2026
CVE-2026-56160
9.1 CRITICAL

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Jul 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.