60653+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users …
The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails …
The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and …
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a …
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro …
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing …
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is …
A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the …
A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS …
In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a …
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a …
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a …
In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if …
In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User …
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with …
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if …
In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has …
In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor …
In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor …
In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor …
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no …
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service …
In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service …
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with …
In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …
In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious …
In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …
In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if …
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if …
In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution …
In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious …
In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious …
In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a …
In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if …
In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if …
A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component …
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator …
Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the …
better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to …
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and …
A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm …
Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A …
A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator …
A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and …
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to …
The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such …
Free website and port scanning — find vulnerabilities before attackers do.