CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-103536
7.3 HIGH

A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. …

Oct 1, 2026
CVE-2026-96561
7.2 HIGH

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, …

Oct 1, 2026
CVE-2026-92245
7.5 HIGH

The Simply Schedule Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.12.32 via the 'recursive' parameter. …

Oct 1, 2026
CVE-2026-103530
7.3 HIGH

A vulnerability was detected in decolua 9Router up to 0.5.55. The affected element is the function fetch of the file src/shared/utils/ssrfGuard.js of the component Search …

Oct 1, 2026
CVE-2026-103591
7.5 HIGH

DeepWiki-Open through commit d92819a contains an unauthenticated arbitrary file read vulnerability in the GET /codemap/file endpoint via the repo_url parameter. Attackers can supply a non-URL …

Sep 30, 2026
CVE-2026-92172
8.8 HIGH

Prior to v66.0.0.733.524 of Meta Horizon OS, OVRMediaService could be induced to send a privileged PendingIntent including a com.oculus.horizon CallerIdentity to an arbitrary application registering …

Sep 30, 2026
CVE-2026-51860
7.5 HIGH

bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Directory Traversal in src/backend/bisheng/linsight/domain/task_exec.py.

Sep 30, 2026
CVE-2026-51853
7.5 HIGH

agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, …

Sep 30, 2026
CVE-2026-51570
8.1 HIGH

modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.

Sep 30, 2026
CVE-2026-51568
8.1 HIGH

modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.

Sep 30, 2026
CVE-2026-103000
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py …

Sep 30, 2026
CVE-2026-102999
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API …

Sep 30, 2026
CVE-2026-102998
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to …

Sep 30, 2026
CVE-2026-102997
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can …

Sep 30, 2026
CVE-2026-102996
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an …

Sep 30, 2026
CVE-2026-102995
7.5 HIGH

pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a …

Sep 30, 2026
CVE-2026-102150
7.2 HIGH

A function in the Kiteworks Advanced Forms component was reachable without authentication. An unauthenticated attacker could potentially use it to carry out a limited set …

Sep 30, 2026
CVE-2026-102143
7.5 HIGH

An unauthenticated attacker could cause a file with attacker-controlled content to be written to the appliance filesystem through an administrative upload handler that did not …

Sep 30, 2026
CVE-2026-102142
7.2 HIGH

A system notification template on the Kiteworks appliance was rendered by a template engine that evaluated expressions contained in the stored template body. An authenticated …

Sep 30, 2026
CVE-2026-102132
7.2 HIGH

An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A …

Sep 30, 2026
CVE-2026-102131
7.2 HIGH

Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator …

Sep 30, 2026
CVE-2026-102130
7.2 HIGH

Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. …

Sep 30, 2026
CVE-2026-102129
7.2 HIGH

A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated …

Sep 30, 2026
CVE-2026-102128
7.5 HIGH

An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not …

Sep 30, 2026
CVE-2026-102127
7.0 HIGH

An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote …

Sep 30, 2026
CVE-2026-102126
8.1 HIGH

A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content …

Sep 30, 2026
CVE-2026-102125
8.8 HIGH

The sandbox that isolates document conversion on a Kiteworks appliance did not fully confine the code running inside it. Code already executing within that sandbox …

Sep 30, 2026
CVE-2026-102123
7.4 HIGH

A Kiteworks appliance setup interface did not confine a user-supplied file path to its intended directory, which could allow an unauthenticated attacker to write a …

Sep 30, 2026
CVE-2026-102121
8.6 HIGH

A form-rendering interface in the Advanced Forms component is reachable without authentication so that published forms can be displayed to anonymous visitors, but it returned …

Sep 30, 2026
CVE-2026-102120
8.8 HIGH

A privilege escalation vulnerability in Kiteworks could have allowed an attacker who had already obtained code execution on one node of a clustered Kiteworks deployment …

Sep 30, 2026
CVE-2026-102119
7.2 HIGH

A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. …

Sep 30, 2026
CVE-2026-102118
7.8 HIGH

A local privilege escalation vulnerability in Kiteworks could have allowed an attacker with an existing shell under a low-privileged service account to escalate to root …

Sep 30, 2026
CVE-2026-102117
7.2 HIGH

On deployments where the remote-support capability is licensed and enabled, an authenticated System Administrator who also possessed the key protecting the submitted data could redirect …

Sep 30, 2026
CVE-2026-102116
7.2 HIGH

-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to …

Sep 30, 2026
CVE-2026-102114
7.2 HIGH

A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful …

Sep 30, 2026
CVE-2026-102113
7.8 HIGH

A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance …

Sep 30, 2026
CVE-2026-102112
7.8 HIGH

A privilege escalation vulnerability in Kiteworks could allow an attacker who has already obtained code execution as an unprivileged backend service account on the appliance …

Sep 30, 2026
CVE-2026-102109
7.1 HIGH

A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a …

Sep 30, 2026
CVE-2026-102108
7.2 HIGH

An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, …

Sep 30, 2026
CVE-2026-102101
8.1 HIGH

Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data …

Sep 30, 2026
CVE-2026-102100
8.7 HIGH

Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user …

Sep 30, 2026
CVE-2026-102099
7.2 HIGH

Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature …

Sep 30, 2026
CVE-2026-102098
7.2 HIGH

Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated …

Sep 30, 2026
CVE-2026-102097
7.2 HIGH

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose …

Sep 30, 2026
CVE-2026-102096
7.2 HIGH

Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not …

Sep 30, 2026
CVE-2026-102094
7.2 HIGH

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load …

Sep 30, 2026
CVE-2026-102093
7.2 HIGH

Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated …

Sep 30, 2026
CVE-2026-102092
8.7 HIGH

Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store crafted content that executes arbitrary …

Sep 30, 2026
CVE-2026-102091
7.5 HIGH

Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue …

Sep 30, 2026
CVE-2026-102089
7.2 HIGH

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.