CVE Database

54056+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-6402
5.3 MEDIUM

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. …

May 12, 2026
CVE-2026-6256
6.4 MEDIUM

The Credits Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the 'credits' shortcode in all versions up to, …

May 12, 2026
CVE-2026-6247
6.4 MEDIUM

The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up …

May 12, 2026
CVE-2026-6237
6.4 MEDIUM

The Quick Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style' attribute of the 'qtbl' shortcode in all versions up to, …

May 12, 2026
CVE-2026-5715
6.4 MEDIUM

The Voyage Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the 'post-content' shortcode in all versions up to, …

May 12, 2026
CVE-2026-5693
5.3 MEDIUM

The Smart Appointment & Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and a nonce validation …

May 12, 2026
CVE-2026-5340
6.4 MEDIUM

The Fancy Image Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `fancy-img-show` shortcode in all versions up to, and including, …

May 12, 2026
CVE-2026-5028
6.5 MEDIUM

The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action …

May 12, 2026
CVE-2026-4920
6.4 MEDIUM

The Next Date plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in all versions up to, and including, 1.0 …

May 12, 2026
CVE-2026-4859
6.4 MEDIUM

The SP Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'design' attribute of the `wpsbd_post_carousel` shortcode in all versions up …

May 12, 2026
CVE-2026-4663
5.3 MEDIUM

The iPOSpays Gateways WC plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.3.7. This is due to the plugin …

May 12, 2026
CVE-2026-4301
4.3 MEDIUM

The Rate Star Review Vote - AJAX Reviews, Votes, Star Ratings plugin for WordPress is vulnerable to Missing Authorization in all versions up to and …

May 12, 2026
CVE-2026-3604
4.9 MEDIUM

The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and …

May 12, 2026
CVE-2026-2300
6.4 MEDIUM

The BJ Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `filter_images()` function in all versions up to, and including, 1.0.9. …

May 12, 2026
CVE-2026-1681
6.1 MEDIUM

Issuing an ICMP ping via the `net ping` shell command to a device's own IPv4 address causes the network stack to recursively re-enter the input …

May 12, 2026
CVE-2026-1185
5.4 MEDIUM

A configuration file on the local file system had improper input validation which could allow code execution and potentially lead to privilege escalation. This vulnerability …

May 12, 2026
CVE-2026-0804
6.7 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be …

May 12, 2026
CVE-2026-0802
6.0 MEDIUM

An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited …

May 12, 2026
CVE-2026-0541
6.7 MEDIUM

ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be …

May 12, 2026
CVE-2026-7257
4.4 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow …

May 12, 2026
CVE-2026-7255
6.5 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** An improper restriction of excessive authentication attempts vulnerability in the web management interface of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 …

May 12, 2026
CVE-2026-40137
6.1 MEDIUM

SAP TAF_APPLAUNCHER within Business Server Pages allows an unauthenticated attacker to craft malicious links that, when clicked by a victim, redirects them to attacker?controlled sites, …

May 12, 2026
CVE-2026-40136
4.3 MEDIUM

SAP Financial Consolidation allows an authenticated attacker to disconnect other users by terminating their sessions temporarily preventing access. However, the application itself cannot be compromised …

May 12, 2026
CVE-2026-40135
6.5 MEDIUM

An OS Command Injection vulnerability exists in the SAP NetWeaver Application Server for ABAP and ABAP Platform that allows an authenticated attacker with administrative access …

May 12, 2026
CVE-2026-40134
4.3 MEDIUM

Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update …

May 12, 2026
CVE-2026-40133
6.3 MEDIUM

Due to missing authorization check in SAP S/4HANA Condition Maintenance, an authenticated attacker could gain unauthorized access to view and modify condition table records, resulting …

May 12, 2026
CVE-2026-40132
5.4 MEDIUM

Due to missing authorization check in SAP Strategic Enterprise Management (Scorecard Wizard in Business Server Pages), an authenticated attacker could access information that they are …

May 12, 2026
CVE-2026-40129
4.3 MEDIUM

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs …

May 12, 2026
CVE-2026-34258
4.7 MEDIUM

SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim …

May 12, 2026
CVE-2026-27682
4.7 MEDIUM

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft …

May 12, 2026
CVE-2026-0502
5.4 MEDIUM

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to …

May 12, 2026
CVE-2026-8349
4.3 MEDIUM

A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation …

May 12, 2026
CVE-2026-8346
6.3 MEDIUM

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The …

May 12, 2026
CVE-2026-8345
6.3 MEDIUM

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of …

May 11, 2026
CVE-2026-43911
6.8 MEDIUM

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive …

May 11, 2026
CVE-2026-43901
6.8 MEDIUM

Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, …

May 11, 2026
CVE-2026-34962
6.2 MEDIUM

barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directory entry …

May 11, 2026
CVE-2026-8344
6.3 MEDIUM

A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function sub_445E7C of the file /goform/formDMZ.cgi. This manipulation causes command …

May 11, 2026
CVE-2026-7010
6.5 MEDIUM

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. The unvalidated inputs are the method …

May 11, 2026
CVE-2026-44695
5.8 MEDIUM

Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state …

May 11, 2026
CVE-2026-43889
6.5 MEDIUM

Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both collectionId and documentId simultaneously and, when published=false, only …

May 11, 2026
CVE-2026-43883
4.2 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.json.php cancels a PayPal billing agreement using an attacker-supplied agreement …

May 11, 2026
CVE-2026-43882
4.3 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler/downloadICS.php endpoint passes attacker-controlled title, description, and joinURL …

May 11, 2026
CVE-2026-43881
5.3 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two unauthenticated paths that disclose the full set …

May 11, 2026
CVE-2026-43880
5.3 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes two branches depending on whether contactForm=1 is submitted. …

May 11, 2026
CVE-2026-43879
5.4 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure their own donation-notification webhook URL …

May 11, 2026
CVE-2026-43878
6.1 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/Meet/iframe.php echoes the attacker-controlled user and pass query parameters unescaped …

May 11, 2026
CVE-2026-43877
5.4 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legacy profile-photo endpoint that accepts a base64 …

May 11, 2026
CVE-2026-43876
6.4 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php takes the raw message POST parameter and passes it …

May 11, 2026
CVE-2026-43875
6.8 MEDIUM

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 …

May 11, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.