CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-54404
7.5 HIGH

Zod schema-validation library through 4.6.5 contains an uncontrolled resource consumption vulnerability that allows attackers to exhaust memory by submitting a large array to an application …

Oct 1, 2026
CVE-2026-93546
8.8 HIGH

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt …

Oct 1, 2026
CVE-2026-73637
7.3 HIGH

Use after free in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause authentication …

Oct 1, 2026
CVE-2026-73636
8.1 HIGH

Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured …

Oct 1, 2026
CVE-2026-63718
7.5 HIGH

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') response smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi and a crafted uwsgi response with Transfer-Encoding. This …

Oct 1, 2026
CVE-2026-63686
7.5 HIGH

A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause …

Oct 1, 2026
CVE-2026-63292
7.5 HIGH

Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial …

Oct 1, 2026
CVE-2026-63045
7.5 HIGH

Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy …

Oct 1, 2026
CVE-2026-59685
7.5 HIGH

Out-of-bounds Write vulnerability in Apache HTTP Server on Windows while processing paths with 8.3 names that may grow when expanded. This issue affects Apache HTTP …

Oct 1, 2026
CVE-2026-56449
7.5 HIGH

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_proxy_html with crafted HTTP response bodies. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Oct 1, 2026
CVE-2026-56153
7.5 HIGH

Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Oct 1, 2026
CVE-2026-48005
7.5 HIGH

Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a …

Oct 1, 2026
CVE-2026-14316
8.1 HIGH

The revoked-key error path builds a human-readable failure reason using sprintf() into a heap buffer. The allocated buffer is too small for the final formatted …

Oct 1, 2026
CVE-2026-12544
7.7 HIGH

A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct …

Oct 1, 2026
CVE-2026-12541
8.2 HIGH

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied …

Oct 1, 2026
CVE-2026-12540
8.2 HIGH

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system …

Oct 1, 2026
CVE-2026-12423
7.5 HIGH

A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw …

Oct 1, 2026
CVE-2026-12405
8.8 HIGH

A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user …

Oct 1, 2026
CVE-2026-103921
7.4 HIGH

GraphQL Tools provides utilities for building, stitching, and mocking GraphQL schemas. Prior to 1.1.35, the executor-legacy-ws buildWSLegacyExecutor() function hardcodes TLS certificate rejection off for Node.js …

Oct 1, 2026
CVE-2026-101888
7.2 HIGH

The Prime Mover plugin for WordPress before 2.2.1 contains a Zip Slip path traversal vulnerability that allows authenticated administrators to write arbitrary files outside the …

Oct 1, 2026
CVE-2026-79896
7.5 HIGH

Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed …

Oct 1, 2026
CVE-2026-47360
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module. When SessionCookieRemove changes across internal redirects, the session cookie may …

Oct 1, 2026
CVE-2026-46729
7.5 HIGH

NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

Oct 1, 2026
CVE-2026-97297
7.6 HIGH

Subscriber Broken Access Control in Gratisfaction <= 4.6.3 versions.

Oct 1, 2026
CVE-2026-97284
8.8 HIGH

Contributor PHP Object Injection in Icegram <= 3.1.31 versions.

Oct 1, 2026
CVE-2026-97277
7.6 HIGH

Subscriber Broken Access Control in Social Boost <= 3.6.2 versions.

Oct 1, 2026
CVE-2026-97273
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.

Oct 1, 2026
CVE-2026-97268
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Premmerce Wishlist for WooCommerce <= 1.1.13 versions.

Oct 1, 2026
CVE-2026-97260
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in MaxGalleria <= 6.5.3 versions.

Oct 1, 2026
CVE-2026-95588
8.6 HIGH

Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.

Oct 1, 2026
CVE-2026-94390
7.2 HIGH

Editor PHP Object Injection in Hide Shipping Method For WooCommerce <= 1.5.4 versions.

Oct 1, 2026
CVE-2026-79899
7.9 HIGH

Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local …

Oct 1, 2026
CVE-2026-67105
7.4 HIGH

HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic …

Oct 1, 2026
CVE-2026-62073
7.5 HIGH

Unauthenticated Broken Access Control in WP Full Stripe Free <= 8.5.6 versions.

Oct 1, 2026
CVE-2026-56589
7.2 HIGH

HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within …

Oct 1, 2026
CVE-2026-103687
7.3 HIGH

A vulnerability has been found in rhukster dom-sanitizer up to 1.0.15. The affected element is the function url of the file src/DOMSanitizer.php of the component …

Oct 1, 2026
CVE-2026-103068
8.8 HIGH

Subscriber Privilege Escalation in ByteCoreStack &#8211; MCP Connector for AI Tools <= 1.2.2 versions.

Oct 1, 2026
CVE-2026-102378
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.

Oct 1, 2026
CVE-2026-100517
7.5 HIGH

Unauthenticated Insecure Direct Object References (IDOR) in Photo Reviews for WooCommerce <= 1.2.30 versions.

Oct 1, 2026
CVE-2026-100514
7.5 HIGH

Unauthenticated Insecure Direct Object References (IDOR) in REST API Log <= 1.7.2 versions.

Oct 1, 2026
CVE-2024-58388
7.5 HIGH

Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the …

Oct 1, 2026
CVE-2026-66246
8.8 HIGH

iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), …

Oct 1, 2026
CVE-2026-102504
7.5 HIGH

Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line …

Oct 1, 2026
CVE-2026-62060
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in captivateaudio Captivate Sync captivatesync-trade allows Blind SQL Injection.This issue affects Captivate …

Oct 1, 2026
CVE-2026-62059
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Blind SQL Injection.This issue affects …

Oct 1, 2026
CVE-2026-103338
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor …

Oct 1, 2026
CVE-2026-103067
8.0 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a …

Oct 1, 2026
CVE-2026-102379
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme BuildKit – Product Builder for WooCommerce – Custom PC Builder …

Oct 1, 2026
CVE-2026-88789
8.6 HIGH

Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xalan) in Apache Camel Quarkus from 3.2.0 before 3.33.3 and from 3.34.0 before …

Oct 1, 2026
CVE-2026-103758
8.1 HIGH

Obot 0.21.1 through 0.24.1 contains an authorization bypass vulnerability that allows authenticated users to reach MCP servers because the checkUI deny list omits the /mcp-connect-composite/ …

Oct 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.