CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-19856
6.5 MEDIUM

The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding …

Oct 2, 2026
CVE-2026-103957
6.2 MEDIUM

Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token …

Oct 2, 2026
CVE-2026-96613
6.5 MEDIUM

The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any …

Oct 2, 2026
CVE-2026-94544
4.2 MEDIUM

Next.js is a React framework for building full-stack web applications. From 16.3.0 until 16.3.8, pending use cache fills for the same key are shared without …

Oct 2, 2026
CVE-2026-94543
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, self-hosted applications using the Pages Router with statically generated …

Oct 2, 2026
CVE-2026-94486
5.4 MEDIUM

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the next dev development server exposes a Model Context Protocol endpoint …

Oct 2, 2026
CVE-2026-94485
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, the `next dev` development server exposes a Model Context Protocol endpoint …

Oct 2, 2026
CVE-2026-94484
4.8 MEDIUM

Next.js is a React framework for building full-stack web applications. From 15.0.0 until 15.5.27 and 16.3.8, applications with a root-level catch-all page and statically generated …

Oct 2, 2026
CVE-2026-94483
6.5 MEDIUM

Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL …

Oct 2, 2026
CVE-2026-51899
4.3 MEDIUM

In SuperAGI v0.0.14 and prior, controller endpoints (/api/agents/create, /api/agents/schedule, /api/agents/delete, /api/agents/edit_schedule, /api/agents/stop_schedule) allow authenticated users from one organization to create, schedule, edit, stop, and delete …

Oct 2, 2026
CVE-2026-104844
5.9 MEDIUM

PostCSS Selector Parser is a CSS selector parser that integrates with PostCSS but does not require it. Prior to 7.1.6, src/parser.js splitWord() can receive a …

Oct 2, 2026
CVE-2026-103629
4.3 MEDIUM

Integer overflow in Skia in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Oct 2, 2026
CVE-2026-103627
6.5 MEDIUM

Information leak in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Oct 2, 2026
CVE-2026-103621
4.3 MEDIUM

Integer overflow in Compositing in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Oct 2, 2026
CVE-2026-5782
5.2 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in MRV Technology Foreign Trade Ltd. Co. TurkHotspot allows Reflected XSS. This issue affects …

Oct 2, 2026
CVE-2026-39717
4.3 MEDIUM

Missing Authorization vulnerability in ThimPress LearnPress learnpress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LearnPress: from n/a through 4.4.9.1.

Oct 2, 2026
CVE-2026-39600
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through …

Oct 2, 2026
CVE-2026-39444
5.4 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a …

Oct 2, 2026
CVE-2026-39439
6.5 MEDIUM

Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7.

Oct 2, 2026
CVE-2026-32585
6.5 MEDIUM

Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Airano MCP Bridge: from n/a through …

Oct 2, 2026
CVE-2026-32584
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded …

Oct 2, 2026
CVE-2026-104638
5.3 MEDIUM

A security vulnerability has been detected in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The impacted element is an unknown function of the file php/sessions.php. The manipulation …

Oct 2, 2026
CVE-2026-104625
6.3 MEDIUM

A security flaw has been discovered in CodeAstro Simple Loan Management System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation …

Oct 2, 2026
CVE-2026-104614
6.3 MEDIUM

A vulnerability was identified in CodeAstro Simple Pharmacy Management System 1.0. This issue affects some unknown processing of the file /SimplePharmacy-PHP/product/delete.php. Such manipulation of the …

Oct 2, 2026
CVE-2026-104613
6.3 MEDIUM

A vulnerability was determined in CodeAstro Simple Pharmacy Management System 1.0. This vulnerability affects unknown code of the file /SimplePharmacy-PHP/product/view.php. This manipulation of the argument …

Oct 2, 2026
CVE-2026-85209
6.5 MEDIUM

Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels. This …

Oct 2, 2026
CVE-2026-11795
5.3 MEDIUM

Observable discrepancy vulnerability in Softtr Informatics Trading Limited Company E-Commerce Pack allows Account Footprinting. This issue affects E-Commerce Pack: through 2026-10-02. NOTE: The vendor was …

Oct 2, 2026
CVE-2026-104612
4.3 MEDIUM

A vulnerability was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file script/academic/core/new_announcement.php of the component Announcement Module. …

Oct 2, 2026
CVE-2026-102798
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Stored XSS.This issue affects ThemeREX Addons: from …

Oct 2, 2026
CVE-2026-102797
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in ThemeREX Group ThemeREX Addons trx_addons allows Server Side Request Forgery.This issue affects ThemeREX Addons: from n/a through 2.46.0.

Oct 2, 2026
CVE-2026-104473
6.1 MEDIUM

YesWiki before 4.5.3 contains multiple reflected cross-site scripting vulnerabilities that allow remote attackers to inject JavaScript through unsanitized parameters such as incomingurl, id, file, tags, …

Oct 2, 2026
CVE-2026-104470
5.0 MEDIUM

YesWiki before 4.6.7 contains a server-side request forgery vulnerability that allows page editors to make the server fetch arbitrary URLs via the url parameter of …

Oct 2, 2026
CVE-2026-104469
6.8 MEDIUM

YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated sessions because login does not regenerate the PHP session ID. Attackers …

Oct 2, 2026
CVE-2026-104468
4.8 MEDIUM

YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse old password reset links because tokens lack expiry timestamps. Attackers who …

Oct 2, 2026
CVE-2026-104466
5.4 MEDIUM

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in formatters/wakka.php that allows users who can edit pages or post comments to inject event handlers …

Oct 2, 2026
CVE-2026-104465
6.1 MEDIUM

YesWiki before 4.6.7 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the field parameter of the mail handler. Attackers …

Oct 2, 2026
CVE-2026-104461
5.4 MEDIUM

YesWiki before 4.6.7 contains a stored cross-site scripting vulnerability in the Bazar FileField, which validates only the upload's file extension and never calls HtmlPurifierService::cleanFile, so …

Oct 2, 2026
CVE-2026-104459
6.5 MEDIUM

YesWiki before 4.6.7 contains a server-side request forgery vulnerability in WebfingerService that allows unauthenticated attackers to trigger HTTPS requests to internal hosts. Attackers can POST …

Oct 2, 2026
CVE-2026-104458
6.5 MEDIUM

YesWiki before 4.6.7 contains a server-side request forgery vulnerability in validateKeyIdUrl() that allows unauthenticated attackers to bypass the SSRF guard using 6to4, NAT64, or IPv4-compatible …

Oct 2, 2026
CVE-2026-104455
5.3 MEDIUM

YesWiki before 4.6.7 contains an access control bypass vulnerability that allows unauthenticated attackers to read restricted page content via the recentchangesrssplus RSS action. Attackers can …

Oct 2, 2026
CVE-2026-104454
5.3 MEDIUM

YesWiki before 4.6.7 contains an algorithmic-complexity denial of service in the wakka.php formatter due to an O(n^2) markdown-link regex. Unauthenticated attackers can submit a small …

Oct 2, 2026
CVE-2026-104453
5.4 MEDIUM

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the admintag action that allows attackers to delete tag associations by luring administrators to crafted …

Oct 2, 2026
CVE-2026-104452
5.4 MEDIUM

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in the filemanager page handler, which deletes page attachments on GET requests without validating a CSRF …

Oct 2, 2026
CVE-2026-104451
4.3 MEDIUM

YesWiki before 4.6.7 contains a cross-site request forgery vulnerability in RevisionsHandler that allows attackers to restore old page revisions through GET requests lacking CSRF token …

Oct 2, 2026
CVE-2026-104450
6.5 MEDIUM

YesWiki before 4.6.7 contains a missing authorization flaw in the pointimage action (tools/attach/actions/pointimage.php), which saves content to an attacker-chosen page with write ACL checks bypassed. …

Oct 2, 2026
CVE-2026-104449
6.5 MEDIUM

YesWiki before 4.6.7 contains an access control vulnerability allowing unauthenticated attackers to overwrite any existing wiki page, including pages whose write ACL restricts editing, via …

Oct 2, 2026
CVE-2026-104446
6.5 MEDIUM

YesWiki before 4.6.7 contains an authentication bypass in the contact mail AJAX handler that allows unauthenticated attackers to send email through the wiki's SMTP server. …

Oct 2, 2026
CVE-2026-104442
5.8 MEDIUM

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary URLs by supplying a syndication …

Oct 2, 2026
CVE-2026-104441
5.3 MEDIUM

YesWiki before 4.6.7 contains an unauthenticated server-side request forgery vulnerability that allows remote attackers to make the server fetch arbitrary hosts and ports via the …

Oct 2, 2026
CVE-2026-104440
5.3 MEDIUM

YesWiki before 4.6.7 contains a blind server-side request forgery vulnerability that allows unauthenticated attackers to make arbitrary server-side requests via the idtypeannonce parameter of /api/entries/bazarlist. …

Oct 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.