CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-100157
6.5 MEDIUM

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due …

Oct 3, 2026
CVE-2026-97344
6.4 MEDIUM

The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta …

Oct 3, 2026
CVE-2026-94239
6.8 MEDIUM

The Loco Translate WordPress plugin before 2.8.9 does not sanitise and escape some bundle configuration values before outputting them back in an admin page, allowing …

Oct 3, 2026
CVE-2026-94238
6.8 MEDIUM

The Loco Translate WordPress plugin before 2.8.9 does not restrict which file paths its translation file routes will read, allowing users granted the Loco Translate …

Oct 3, 2026
CVE-2026-92923
6.3 MEDIUM

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users …

Oct 3, 2026
CVE-2026-92437
5.3 MEDIUM

The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart …

Oct 3, 2026
CVE-2026-91108
4.3 MEDIUM

The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions …

Oct 3, 2026
CVE-2026-88782
6.8 MEDIUM

The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link …

Oct 3, 2026
CVE-2026-86832
5.3 MEDIUM

The MetForm WordPress plugin before 4.3.1 does not properly restrict access to form submission data, allowing unauthenticated attackers to view submitter information through the REST …

Oct 3, 2026
CVE-2026-85568
6.8 MEDIUM

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated …

Oct 3, 2026
CVE-2026-85015
6.6 MEDIUM

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access …

Oct 3, 2026
CVE-2026-11399
4.3 MEDIUM

The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 …

Oct 3, 2026
CVE-2026-103909
6.1 MEDIUM

The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based …

Oct 3, 2026
CVE-2026-103888
6.1 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'woosq-redirect' parameter in all versions up to, …

Oct 3, 2026
CVE-2026-103293
6.8 MEDIUM

The MPG WordPress plugin before 4.2.3 does not validate that the dataset source supplied when importing a project is a remote URL before treating it …

Oct 3, 2026
CVE-2026-101357
4.9 MEDIUM

The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'seopress_google_analytics_matomo_id' parameter in all versions …

Oct 3, 2026
CVE-2026-101162
6.4 MEDIUM

The WP Ultimate Review WordPress plugin before 2.4.4 does not escape some of its review overview settings before outputting them in posts, which could allow …

Oct 3, 2026
CVE-2026-100152
6.5 MEDIUM

The The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for …

Oct 3, 2026
CVE-2026-100149
5.3 MEDIUM

The WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Oct 3, 2026
CVE-2026-100148
6.4 MEDIUM

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reviews[].text' parameter in all versions up to, and …

Oct 3, 2026
CVE-2025-12828
6.4 MEDIUM

The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, …

Oct 3, 2026
CVE-2026-92826
6.1 MEDIUM

The EWWW Image Optimizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Parameter Key in all versions up to, and including, 8.7.7 …

Oct 3, 2026
CVE-2026-92727
6.4 MEDIUM

The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site …

Oct 3, 2026
CVE-2026-92551
6.1 MEDIUM

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site …

Oct 3, 2026
CVE-2026-92538
6.1 MEDIUM

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Reflected DOM-Based Cross-Site Scripting via the 'orderby' …

Oct 3, 2026
CVE-2026-95865
6.5 MEDIUM

The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to blind SQL Injection via 'fields[][value]' Parameter in all …

Oct 3, 2026
CVE-2026-94539
6.5 MEDIUM

The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter …

Oct 3, 2026
CVE-2026-94378
6.4 MEDIUM

The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter …

Oct 3, 2026
CVE-2026-92243
6.1 MEDIUM

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, …

Oct 3, 2026
CVE-2026-100180
5.4 MEDIUM

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Oct 3, 2026
CVE-2026-105030
5.3 MEDIUM

Kener 4.0.0 before 4.1.6 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve hidden or inactive monitor data by querying dashboard API handlers …

Oct 3, 2026
CVE-2026-105029
4.3 MEDIUM

UVdesk support-center-bundle before 1.1.3.3 contains an insecure direct object reference vulnerability in the rateTicket action of Controller/Ticket.php that allows authenticated customers to rate other customers' …

Oct 3, 2026
CVE-2026-104479
5.4 MEDIUM

Shopclass before 6.2.0 contains a stored cross-site scripting vulnerability that allows self-registered non-admin users to inject scripts into item listing descriptions when frontend TinyMCE is …

Oct 3, 2026
CVE-2026-104477
6.1 MEDIUM

Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed …

Oct 3, 2026
CVE-2026-104476
5.9 MEDIUM

Backdrop CMS before 1.35.1 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve configuration export archives left on the server after transfer. Attackers …

Oct 3, 2026
CVE-2026-104475
5.4 MEDIUM

IDURAR ERP CRM through 4.1.1 contains a stored cross-site scripting vulnerability that allows authenticated users to inject scripts by uploading unsanitized SVG files. Attackers can …

Oct 3, 2026
CVE-2026-104474
6.7 MEDIUM

OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the …

Oct 3, 2026
CVE-2026-105049
5.8 MEDIUM

Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public …

Oct 2, 2026
CVE-2026-105048
4.0 MEDIUM

The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).

Oct 2, 2026
CVE-2026-94594
4.0 MEDIUM

Armatura One's message broker logs client connection credentials and the associated password in plain text during normal operation. Any party with read access to this …

Oct 2, 2026
CVE-2026-93474
6.5 MEDIUM

Charging station authentication identifiers are publicly accessible via web-based mapping platforms.

Oct 2, 2026
CVE-2026-105046
4.3 MEDIUM

Kentico Xperience 13 before 13.0.216 lacks object-level authorization checks for administration API endpoints.

Oct 2, 2026
CVE-2026-82045
6.5 MEDIUM

UTMStack before 11.2.16 contains a JPQL injection vulnerability that allows authenticated attackers to read arbitrary entity data by exploiting UtmNetworkScanService.searchPropertyValues(), which builds a JPQL query …

Oct 2, 2026
CVE-2026-82043
5.3 MEDIUM

UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST …

Oct 2, 2026
CVE-2026-104874
5.3 MEDIUM

Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl …

Oct 2, 2026
CVE-2026-82040
5.0 MEDIUM

UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or …

Oct 2, 2026
CVE-2026-12392
5.3 MEDIUM

An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret …

Oct 2, 2026
CVE-2026-104872
5.8 MEDIUM

OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose, @opentelemetry/instrumentation-mysql, …

Oct 2, 2026
CVE-2026-103918
6.5 MEDIUM

oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin …

Oct 2, 2026
CVE-2026-103036
6.5 MEDIUM

oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer …

Oct 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.