CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81740
5.3 MEDIUM

The Paytm Payment Gateway WordPress plugin before 2.8.9 does not verify that payment callbacks genuinely originate from the payment provider when its secret key has …

Oct 2, 2026
CVE-2026-78471
5.4 MEDIUM

The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to …

Oct 2, 2026
CVE-2026-13718
6.8 MEDIUM

The Tabs Responsive WordPress plugin through 2.5 does not sanitize the content of WooCommerce product tabs before storing and rendering it, allowing a shop manager …

Oct 2, 2026
CVE-2026-104054
6.3 MEDIUM

A security flaw has been discovered in calcom cal.diy up to 6.2.0. This affects the function doesUserIdHaveAccessToBooking of the file BookingAccessService.ts of the component PBAC …

Oct 2, 2026
CVE-2026-104053
6.3 MEDIUM

A vulnerability was identified in itsourcecode Pet Shop Management System 1.0. The impacted element is an unknown function of the file admin_reservefilter.php. Such manipulation of …

Oct 2, 2026
CVE-2026-104052
6.3 MEDIUM

A vulnerability was determined in itsourcecode Pet Shop Management System 1.0. The affected element is an unknown function of the file admin_reject_completed.php. This manipulation of …

Oct 2, 2026
CVE-2026-103760
5.9 MEDIUM

Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. …

Oct 1, 2026
CVE-2025-71427
6.8 MEDIUM

Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths …

Oct 1, 2026
CVE-2026-51896
6.5 MEDIUM

infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.

Oct 1, 2026
CVE-2026-51895
6.5 MEDIUM

Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.

Oct 1, 2026
CVE-2026-51894
6.5 MEDIUM

infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access …

Oct 1, 2026
CVE-2026-51892
6.5 MEDIUM

infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.

Oct 1, 2026
CVE-2026-51878
4.3 MEDIUM

deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate …

Oct 1, 2026
CVE-2026-104356
5.9 MEDIUM

PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in …

Oct 1, 2026
CVE-2026-104002
5.3 MEDIUM

A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that …

Oct 1, 2026
CVE-2026-104183
5.1 MEDIUM

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with …

Oct 1, 2026
CVE-2026-104182
6.2 MEDIUM

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js …

Oct 1, 2026
CVE-2026-104181
5.4 MEDIUM

Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently …

Oct 1, 2026
CVE-2026-93832
4.4 MEDIUM

A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.

Oct 1, 2026
CVE-2026-82358
6.5 MEDIUM

RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions …

Oct 1, 2026
CVE-2026-82357
6.5 MEDIUM

RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user …

Oct 1, 2026
CVE-2026-55251
6.5 MEDIUM

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs …

Oct 1, 2026
CVE-2026-102671
5.3 MEDIUM

The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.

Oct 1, 2026
CVE-2026-102670
4.3 MEDIUM

Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.

Oct 1, 2026
CVE-2026-102669
5.3 MEDIUM

Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.

Oct 1, 2026
CVE-2026-102668
5.3 MEDIUM

The Joyland AI app accepts any TLS certificates from any server without validation.

Oct 1, 2026
CVE-2026-102666
6.5 MEDIUM

The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push …

Oct 1, 2026
CVE-2026-100251
6.5 MEDIUM

Wormhole.app as deployed before 2026-08-22 misconfigures the coturn TURN server and does not properly restrict TCP relay peers, allowing an unauthenticated attacker to access instance …

Oct 1, 2026
CVE-2026-104058
5.3 MEDIUM

Podgrab contains a missing authentication vulnerability in which the /ws WebSocket route is registered on the root gin engine instead of the BasicAuth-protected router group, …

Oct 1, 2026
CVE-2026-56098
4.3 MEDIUM

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While …

Oct 1, 2026
CVE-2026-56097
6.5 MEDIUM

A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input …

Oct 1, 2026
CVE-2026-12545
6.7 MEDIUM

A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due …

Oct 1, 2026
CVE-2026-12542
5.3 MEDIUM

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The …

Oct 1, 2026
CVE-2026-103884
6.5 MEDIUM

A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate …

Oct 1, 2026
CVE-2026-79768
5.3 MEDIUM

Path equivalence: '/./' (single dot directory) vulnerability in Apache HTTP Server's mod_userdir module when configured with absolute non-wildcard UserDir directive (the 2nd form in https://httpd.apache.org/docs/2.4/mod/mod_userdir.html#userdir) …

Oct 1, 2026
CVE-2026-77387
4.0 MEDIUM

geopy is a geocoding library for Python. Prior to 2.5.0, geopy.Point and Point.from_string() can spend excessive CPU time due to inefficient regular-expression behavior when an …

Oct 1, 2026
CVE-2026-67171
5.3 MEDIUM

HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable …

Oct 1, 2026
CVE-2026-58415
5.3 MEDIUM

Internal state files accessible to external parties in mod_dav_fs in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows a remote client …

Oct 1, 2026
CVE-2026-101890
5.4 MEDIUM

The Prime Mover plugin for WordPress before 2.2.1 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by injecting an unescaped …

Oct 1, 2026
CVE-2026-101889
6.5 MEDIUM

The Prime Mover plugin for WordPress before 2.2.1 contains a path traversal vulnerability that allows authenticated administrators to delete arbitrary directories by importing a crafted …

Oct 1, 2026
CVE-2025-31980
4.3 MEDIUM

HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, …

Oct 1, 2026
CVE-2026-9864
4.8 MEDIUM

Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations …

Oct 1, 2026
CVE-2026-42528
4.3 MEDIUM

A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child …

Oct 1, 2026
CVE-2026-17053
4.4 MEDIUM

The SMBus driver API exposed smbus_smbalert_remove_cb() and smbus_host_notify_remove_cb() as Zephyr syscalls. Their verifiers in drivers/smbus/smbus_handlers.c validated only the dev argument with K_SYSCALL_OBJ(dev, K_OBJ_DRIVER_SMBUS) and forwarded …

Oct 1, 2026
CVE-2026-103690
6.3 MEDIUM

A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the …

Oct 1, 2026
CVE-2026-103505
6.5 MEDIUM

Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-driver) v3.1.0 through v3.4.2 might allow remote authenticated users with …

Oct 1, 2026
CVE-2026-97281
6.3 MEDIUM

Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.

Oct 1, 2026
CVE-2026-97280
6.5 MEDIUM

Missing Authorization vulnerability in Mamunur Rashid Review Schema review-schema allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Review Schema: 3.1.0.

Oct 1, 2026
CVE-2026-97269
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in WPFunnels <= 3.13.1 versions.

Oct 1, 2026
CVE-2026-97258
6.5 MEDIUM

Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.

Oct 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.