CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-104845
7.5 HIGH

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as …

Oct 2, 2026
CVE-2026-103631
8.8 HIGH

Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Oct 2, 2026
CVE-2026-103625
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Oct 2, 2026
CVE-2026-103624
8.3 HIGH

Use after free in Contextual Tasks in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker who had compromised the renderer process …

Oct 2, 2026
CVE-2026-103623
8.8 HIGH

Use after free in MediaStream in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 2, 2026
CVE-2026-103622
8.8 HIGH

Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Oct 2, 2026
CVE-2026-101104
7.7 HIGH

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do …

Oct 2, 2026
CVE-2026-104637
7.3 HIGH

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation …

Oct 2, 2026
CVE-2026-104026
7.8 HIGH

In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a …

Oct 2, 2026
CVE-2026-94422
8.8 HIGH

An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus …

Oct 2, 2026
CVE-2026-93875
7.2 HIGH

The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to …

Oct 2, 2026
CVE-2026-85215
7.1 HIGH

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GG Soft Software Services Inc. Paperwork allows SQL Injection. This issue …

Oct 2, 2026
CVE-2026-104609
7.3 HIGH

A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function get of the file edit_accounts.php. This manipulation of the argument …

Oct 2, 2026
CVE-2026-104472
7.5 HIGH

YesWiki before 4.6.7 contains a missing authorization vulnerability in the attachment download handler that allows unauthenticated attackers to bypass page read ACLs. Attackers can request …

Oct 2, 2026
CVE-2026-104471
7.2 HIGH

YesWiki before 4.6.7 contains an unrestricted file upload vulnerability that allows authenticated admins to write remote files into the web-accessible files/ directory via Bazar CSV …

Oct 2, 2026
CVE-2026-104467
8.1 HIGH

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. …

Oct 2, 2026
CVE-2026-104464
8.6 HIGH

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to make server-side GET requests by supplying an unvalidated actor URL to …

Oct 2, 2026
CVE-2026-104463
7.0 HIGH

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows unauthenticated attackers to trigger server requests by sending signed Follow activities to the public …

Oct 2, 2026
CVE-2026-104462
7.5 HIGH

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar nuagetag action, which concatenates the unescaped tags attribute into a raw SQL IN clause. …

Oct 2, 2026
CVE-2026-104460
7.5 HIGH

YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}} action because Bazar list option ids are concatenated into SQL REGEXP/LIKE clauses in …

Oct 2, 2026
CVE-2026-104457
8.6 HIGH

YesWiki before 4.6.7 contains an SQL injection vulnerability in the Bazar filtertags action, which wraps unescaped filterN attribute tokens in quotes and concatenates them into …

Oct 2, 2026
CVE-2026-104456
7.6 HIGH

YesWiki before 4.6.7 contains a second-order SQL injection vulnerability in AclService::updateRequestWithACL, where a stored username is concatenated unescaped into a read-ACL LIKE clause. Attackers can …

Oct 2, 2026
CVE-2026-104448
8.1 HIGH

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the ajaxdeletepage handler, which permanently deletes a page on any GET request carrying a jsonp_callback …

Oct 2, 2026
CVE-2026-104447
7.1 HIGH

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the autoupdate UpdateAction that allows attackers to delete installed packages via unprotected GET requests. Attackers …

Oct 2, 2026
CVE-2026-104445
8.2 HIGH

YesWiki before 4.6.7 contains an authentication bypass vulnerability in the ActivityPub inbox that fails to bind the verified HTTP signature signer to the activity actor. …

Oct 2, 2026
CVE-2026-104444
7.1 HIGH

YesWiki before 4.6.7 contains an authorization bypass vulnerability in the comments API editComment route that allows authenticated low-privilege users to overwrite arbitrary pages or comments …

Oct 2, 2026
CVE-2026-104443
8.1 HIGH

YesWiki before 4.6.7 contains an empty-filter scope bypass in the triples delete API that allows any authenticated user to delete or forge arbitrary semantic triples …

Oct 2, 2026
CVE-2026-104437
7.4 HIGH

Zebra before 4.4.0 contains a consensus divergence vulnerability in V5 transparent signature verification, computing a ZIP-244 digest for SIGHASH_SINGLE inputs lacking corresponding outputs instead of …

Oct 2, 2026
CVE-2026-104435
7.4 HIGH

Zebra zebrad 4.4.0 and zebra-script 6.0.0 fail to enforce a ZIP-244 consensus rule, accepting V5 transparent inputs signed with SIGHASH_SINGLE that lack a corresponding output. …

Oct 2, 2026
CVE-2026-104431
7.5 HIGH

Zebra before 6.0.0 contains a denial of service vulnerability that allows unauthenticated peers to stall Tokio workers by submitting mempool transactions requiring expensive synchronous script …

Oct 2, 2026
CVE-2026-104430
7.5 HIGH

Zebra zebrad 4.5.0 and zebra-script 7.0.0 count P2SH redeem script signature operations in legacy mode rather than zcashd's accurate P2SH mode, overcounting CHECKMULTISIG preceded by …

Oct 2, 2026
CVE-2026-104423
7.5 HIGH

Zebra (zebrad) before 6.2.1 contains an asymmetric resource consumption vulnerability that allows unauthenticated peers to stall block verification by pushing V6 mempool transactions with invalid …

Oct 2, 2026
CVE-2026-104422
7.5 HIGH

The block sync download path in Zebra (zebrad) before 6.3.0 reads a block's height from its unvalidated coinbase scriptSig and drops blocks that appear too …

Oct 2, 2026
CVE-2026-104418
7.2 HIGH

Ghost from 6.10.3 before 6.64.0 contains a remote code execution vulnerability that allows authenticated administrators to run code by abusing theme translation file loading. Attackers …

Oct 2, 2026
CVE-2026-104416
7.5 HIGH

Ghost from 4.39.0 before 6.64.0 contains an information disclosure vulnerability in the Admin API that allows staff users to view secret tokens of pending staff …

Oct 2, 2026
CVE-2026-104414
8.1 HIGH

Ghost from 2.5.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows attackers to inject untrusted scripts into post content via oEmbed photo responses. …

Oct 2, 2026
CVE-2026-104413
7.3 HIGH

Ghost from 5.94.0 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users, including Contributors, to host arbitrary HTML by abusing bookmark card …

Oct 2, 2026
CVE-2026-104411
7.3 HIGH

Ghost from 6.22.1 before 6.64.0 contains a stored cross-site scripting vulnerability that allows staff users to host scripts by uploading files served with extension-derived content …

Oct 2, 2026
CVE-2026-104410
7.5 HIGH

SiYuan before 3.8.5 contains an information disclosure vulnerability that allows publish readers to read password-protected and publish-disabled database rows via the /api/export/preview endpoint. Attackers can …

Oct 2, 2026
CVE-2026-94651
7.5 HIGH

improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. …

Oct 2, 2026
CVE-2026-85494
7.5 HIGH

Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default …

Oct 2, 2026
CVE-2026-87920
7.2 HIGH

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Output-Buffer Regex Rewrite in all versions up to, …

Oct 2, 2026
CVE-2026-80298
8.8 HIGH

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows SQL Injection. This …

Oct 2, 2026
CVE-2026-103885
7.5 HIGH

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. A LDAP server using the LDAP API (like Apache DS) may consume 100% of a CPU …

Oct 2, 2026
CVE-2026-103880
7.5 HIGH

Asymmetric Resource Consumption vulnerability in Apache Directory LDAP API. Storing a password using the bcrypt algorithm with a high force like 30 in a LDAP …

Oct 2, 2026
CVE-2026-103878
7.5 HIGH

Cleartext transmission of sensitive information vulnerability in Apache Directory LDAP API. A StartTLS extended operation started after a Search request has been sent can lead …

Oct 2, 2026
CVE-2026-103552
7.3 HIGH

Stack Overflow vulnerability in Apache Directory LDAP API. Before binding, a client can send a deeply nested search filter that overflows the stack in the …

Oct 2, 2026
CVE-2026-102731
7.5 HIGH

Memory allocation with excessive size value vulnerability in Apache Directory LDAP API. A malicious peer (or a MITM) can send a small BER-encoded response causing …

Oct 2, 2026
CVE-2026-80443
7.4 HIGH

Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot …

Oct 2, 2026
CVE-2026-97663
7.2 HIGH

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, …

Oct 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.