CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-103757
7.7 HIGH

Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. …

Oct 1, 2026
CVE-2026-103292
8.0 HIGH

Ghost versions from 0.5.3 through versions prior to 6.50.0 fail to sanitize the data placed in the JSON-LD HTML tag emitted by the {{ghost_head}} helper. …

Oct 1, 2026
CVE-2026-103286
7.3 HIGH

Ghost versions from 2.21.0 before 6.56.0 contain a privilege escalation vulnerability in the notifications system that allows low-privilege staff users to escalate to higher-privilege staff …

Oct 1, 2026
CVE-2026-103283
8.1 HIGH

Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff users to log in as any other staff user with only …

Oct 1, 2026
CVE-2026-103278
7.3 HIGH

Ghost versions 5.8.0 before 6.34.0 contain an input validation vulnerability in the admin iframe that allows attackers to take over staff user accounts. Attackers with …

Oct 1, 2026
CVE-2026-103277
8.1 HIGH

Ghost versions from 2.5.0 before 6.34.0 contain an untrusted script execution vulnerability in the oEmbed preview feature that fails to sandbox externally hosted scripts. Attackers …

Oct 1, 2026
CVE-2026-103272
7.5 HIGH

Ghost versions from 2.10.0 before 6.63.0 contain a staff enumeration vulnerability in the content API that allows unauthenticated attackers to leak user data. Attackers can …

Oct 1, 2026
CVE-2026-103271
7.5 HIGH

Ghost versions from 4.0.0 before 6.63.0 contain a content API vulnerability that allows unauthenticated visitors to access gated post content. Attackers can bypass content restrictions …

Oct 1, 2026
CVE-2026-103268
8.8 HIGH

Ghost versions before 6.62.0 contain an authentication bypass vulnerability that allows suspended staff users to reactivate their accounts through self-service password reset. Attackers with suspended …

Oct 1, 2026
CVE-2026-103266
7.1 HIGH

Ghost versions 5.2.0 through versions prior to 6.62.0 allow a remote attacker, without authentication, to abuse the Stripe Checkout flow to attach a paid subscription …

Oct 1, 2026
CVE-2026-103262
7.5 HIGH

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed …

Oct 1, 2026
CVE-2026-103259
7.6 HIGH

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver …

Oct 1, 2026
CVE-2026-103257
7.7 HIGH

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to …

Oct 1, 2026
CVE-2026-103256
7.1 HIGH

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to …

Oct 1, 2026
CVE-2026-103253
8.7 HIGH

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table …

Oct 1, 2026
CVE-2026-103252
7.7 HIGH

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves …

Oct 1, 2026
CVE-2026-103251
7.1 HIGH

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for …

Oct 1, 2026
CVE-2026-103250
8.1 HIGH

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that …

Oct 1, 2026
CVE-2026-103249
7.6 HIGH

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown …

Oct 1, 2026
CVE-2026-103247
8.5 HIGH

n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared …

Oct 1, 2026
CVE-2026-103246
7.7 HIGH

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to …

Oct 1, 2026
CVE-2026-103082
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: …

Oct 1, 2026
CVE-2026-96577
7.1 HIGH

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of …

Oct 1, 2026
CVE-2026-92144
7.2 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in …

Oct 1, 2026
CVE-2026-103493
8.1 HIGH

In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible

Oct 1, 2026
CVE-2026-103490
7.2 HIGH

In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links

Oct 1, 2026
CVE-2026-103488
7.1 HIGH

In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues

Oct 1, 2026
CVE-2026-97661
7.2 HIGH

The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Form Field in all versions up to, …

Oct 1, 2026
CVE-2026-96813
7.2 HIGH

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mark on …

Oct 1, 2026
CVE-2026-96573
7.2 HIGH

The Appointment Hour Booking – Booking Calendar plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar …

Oct 1, 2026
CVE-2026-95687
8.8 HIGH

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and …

Oct 1, 2026
CVE-2026-92244
7.2 HIGH

The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Billing First Name / Last Name / …

Oct 1, 2026
CVE-2026-85235
7.2 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field …

Oct 1, 2026
CVE-2026-15983
8.1 HIGH

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, …

Oct 1, 2026
CVE-2026-14995
7.2 HIGH

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient …

Oct 1, 2026
CVE-2026-103431
7.7 HIGH

colmux in collectl before 4.3.20.2 does not sanitize ANSI/VT100 terminal escape sequences in data received from remote collectl instances before displaying it, allowing a local …

Oct 1, 2026
CVE-2026-93882
7.5 HIGH

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up …

Oct 1, 2026
CVE-2026-19807
8.8 HIGH

The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This …

Oct 1, 2026
CVE-2026-96255
7.5 HIGH

The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the …

Oct 1, 2026
CVE-2026-92412
7.1 HIGH

The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated …

Oct 1, 2026
CVE-2026-89296
8.6 HIGH

The Pro Like Button WordPress plugin before 2.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated …

Oct 1, 2026
CVE-2026-85679
7.2 HIGH

The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due …

Oct 1, 2026
CVE-2026-81809
7.5 HIGH

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not properly escape data taken from payment callbacks before using it in a SQL statement, and …

Oct 1, 2026
CVE-2026-81739
7.5 HIGH

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not sanitize and escape data it stores from payment callbacks before outputting it in an admin …

Oct 1, 2026
CVE-2026-80276
7.5 HIGH

Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this …

Oct 1, 2026
CVE-2026-80275
8.8 HIGH

Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated …

Oct 1, 2026
CVE-2026-19253
8.7 HIGH

The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, …

Oct 1, 2026
CVE-2026-101147
8.8 HIGH

The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the …

Oct 1, 2026
CVE-2026-82828
8.8 HIGH

Hitachi Coding Software Suite contains an Incorrect Authorization vulnerability that allows an unprivileged user to perform administrator-level operations. This issue affects Hitachi Coding Software Suite: …

Oct 1, 2026
CVE-2026-82826
7.5 HIGH

Hitachi Coding Software Suite contains a vulnerability related to the Cleartext Transmission of Sensitive Information which allows an attacker to eavesdrop on with authentication credentials …

Oct 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.