CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-104439
5.3 MEDIUM

YesWiki before 4.6.7 contains a user enumeration vulnerability in LostPasswordAction.php that allows unauthenticated attackers to confirm registered email addresses through differing responses. Attackers can submit …

Oct 2, 2026
CVE-2026-104438
5.3 MEDIUM

YesWiki before 4.6.7 contains a missing authorization vulnerability in the listpagestag and includepages actions of the tags tool, which enumerate pages without applying read-ACL filtering. …

Oct 2, 2026
CVE-2026-104434
6.5 MEDIUM

ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing …

Oct 2, 2026
CVE-2026-104432
5.3 MEDIUM

Zebra before 6.3.0 contains an improper exceptional condition check in ChainSync::obtain_tips that discards valid one-hash FindBlocks responses, falsely reporting close-to-tip status. Peers returning only the …

Oct 2, 2026
CVE-2026-104429
5.3 MEDIUM

Zebra (zebrad) 5.0.0 before 6.0.0-rc.0 does not apply its per-peer mempool admission cap to transactions received as direct P2P tx messages, because these are queued …

Oct 2, 2026
CVE-2026-104428
5.3 MEDIUM

The getblock RPC method in zebra-rpc before 11.0.0, used by the Zcash Foundation's Zebra node, panics on verbosity 2 for a side-chain block because the …

Oct 2, 2026
CVE-2026-104427
5.9 MEDIUM

Zebra before 6.1.0 contains an incomplete cleanup vulnerability in the state write task that allows remote unauthenticated peers to stall node synchronization by poisoning parent_error_map. …

Oct 2, 2026
CVE-2026-104426
5.9 MEDIUM

Zebra before 6.1.0 contains an inefficient algorithmic complexity vulnerability in remaining_transaction_value that clones the entire block-level spent-UTXO map per transaction during contextual verification. Attackers can …

Oct 2, 2026
CVE-2026-104425
5.3 MEDIUM

ZcashFoundation Zebra before 6.1.0 contains a resource exhaustion vulnerability that allows unauthenticated peers to degrade block processing by pushing transactions with invalid Orchard proofs without …

Oct 2, 2026
CVE-2026-104421
5.3 MEDIUM

Zebra before 6.2.1 contains an incomplete cleanup vulnerability that allows unauthenticated peers to block downloading of valid blocks by leaving rejected hashes in SentHashes. Attackers …

Oct 2, 2026
CVE-2026-104420
5.3 MEDIUM

Zebra before 6.3.0 contains a protection mechanism failure that allows unauthenticated peers to evade misbehavior scoring by supplying invalid gossiped blocks. The inbound cleanup step …

Oct 2, 2026
CVE-2026-104419
4.8 MEDIUM

Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever …

Oct 2, 2026
CVE-2026-104417
4.9 MEDIUM

Ghost from 1.20.0 before 6.64.0 contains a path traversal vulnerability in theme translation file loading that allows authenticated administrators to read JSON files outside the …

Oct 2, 2026
CVE-2026-104412
4.3 MEDIUM

Ghost 0.5.0 before 6.64.0 does not correctly restrict staff role assignment, allowing users with the Editor or Super Editor role to assign their own role …

Oct 2, 2026
CVE-2026-103763
5.8 MEDIUM

SiYuan before v3.8.5 contains an information disclosure vulnerability that allows read-only publish readers to learn metadata of publish-excluded documents through the getNotebookInfo endpoint. Attackers, including …

Oct 2, 2026
CVE-2026-103762
5.3 MEDIUM

SiYuan before v3.8.5 contains a missing authorization vulnerability in the getRefCreateSavePath, getShorthandSavePath, and getDocCreateSavePath endpoints that allows read-only publish visitors to learn unpublished notebook box …

Oct 2, 2026
CVE-2026-97876
6.4 MEDIUM

A local attacker with control over GRUB's configuration can bypass lockdown restrictions when booting with Secure Boot and load an unsigned GRUB module, while GRUB …

Oct 2, 2026
CVE-2026-104606
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Online Admission System Project 1.0. The impacted element is an unknown function of the file confirm.php. The …

Oct 2, 2026
CVE-2026-97652
6.1 MEDIUM

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions …

Oct 2, 2026
CVE-2026-94405
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.

Oct 2, 2026
CVE-2026-94180
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Monetizemore Advanced Ads allows Retrieve Embedded Sensitive Data. This issue affects Advanced Ads: from n/a through 2.0.26.

Oct 2, 2026
CVE-2026-85492
6.1 MEDIUM

The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress …

Oct 2, 2026
CVE-2026-104403
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LearnPress: from n/a through 4.4.9.

Oct 2, 2026
CVE-2026-95512
5.5 MEDIUM

A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening …

Oct 2, 2026
CVE-2026-80464
4.9 MEDIUM

Server-Side request forgery (SSRF) vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Server Side Request Forgery. This issue affects Sef - AI Chatbot …

Oct 2, 2026
CVE-2026-80337
5.3 MEDIUM

Missing Authorization vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sef - AI …

Oct 2, 2026
CVE-2026-97634
6.5 MEDIUM

The Event Tickets and Registration plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, …

Oct 2, 2026
CVE-2026-97338
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to …

Oct 2, 2026
CVE-2026-96647
6.4 MEDIUM

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[remark]' Parameter in all versions up …

Oct 2, 2026
CVE-2026-94432
5.3 MEDIUM

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up …

Oct 2, 2026
CVE-2026-93880
6.1 MEDIUM

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via '{{GET:}}' Dynamic Placeholder in all versions up …

Oct 2, 2026
CVE-2026-12951
6.5 MEDIUM

The Dc Woocommerce Multi Vendor plugin for WordPress is vulnerable to SQL Injection via the 'order_by' parameter of the /multivendorx/v1/compliance/report-abuse REST endpoint in versions up …

Oct 2, 2026
CVE-2026-97219
4.3 MEDIUM

The MStore API WordPress plugin before 4.22.1 does not restrict which fields of an order a customer may update, allowing any authenticated user with a …

Oct 2, 2026
CVE-2026-92924
5.4 MEDIUM

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to …

Oct 2, 2026
CVE-2026-91020
5.3 MEDIUM

The WebToffee Gift Cards for WooCommerce WordPress plugin before 1.3.1 does not validate a user-supplied gift card amount server-side before using it as the cart-item …

Oct 2, 2026
CVE-2026-90987
5.3 MEDIUM

The Easy PayPal & Stripe Buy Now Button WordPress plugin before 2.0.6 does not derive the payment amount on the server, taking it from a …

Oct 2, 2026
CVE-2026-90952
5.3 MEDIUM

The WP Edit Password Protected WordPress plugin before 2.0.7 does not enforce its site-wide access restriction on the WordPress REST API, allowing unauthenticated users to …

Oct 2, 2026
CVE-2026-85005
5.4 MEDIUM

The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any …

Oct 2, 2026
CVE-2026-84740
6.5 MEDIUM

The Events Calendar WordPress plugin before 6.17.5.1 does not validate or sanitise data submitted to an unauthenticated AJAX action before merging it into its rendering …

Oct 2, 2026
CVE-2026-79618
4.3 MEDIUM

The WP User Frontend WordPress plugin before 4.3.12 does not enforce its subscription-purchase requirement in one of its post-creation handlers, allowing authenticated users with subscriber-level …

Oct 2, 2026
CVE-2026-1661
4.3 MEDIUM

The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin …

Oct 2, 2026
CVE-2026-13413
5.3 MEDIUM

The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing …

Oct 2, 2026
CVE-2026-97318
6.1 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it and later redirecting …

Oct 2, 2026
CVE-2026-97317
5.3 MEDIUM

The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it embeds in public …

Oct 2, 2026
CVE-2026-94298
6.2 MEDIUM

The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and later using it in …

Oct 2, 2026
CVE-2026-91022
6.8 MEDIUM

The Motors WordPress plugin before 1.4.124 does not sanitise and escape a listing badge setting before outputting it inside an HTML attribute, allowing users with …

Oct 2, 2026
CVE-2026-90988
5.3 MEDIUM

The Request a Quote WordPress plugin through 2.5.6 does not perform an authorization check on one of its unauthenticated AJAX handlers, allowing unauthenticated users to …

Oct 2, 2026
CVE-2026-85016
6.8 MEDIUM

The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared …

Oct 2, 2026
CVE-2026-85004
4.3 MEDIUM

The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated …

Oct 2, 2026
CVE-2026-84925
6.1 MEDIUM

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'lang' parameter in all versions …

Oct 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.