CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-97251
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Bus Ticket Booking with Seat Reservation <= 5.9.3 versions.

Oct 1, 2026
CVE-2026-79900
6.5 MEDIUM

boks_ksllogsd accepts a checksum algorithm name in the MD field of an authenticated KSL start message. Affected releases verify that OpenSSL recognizes the digest name …

Oct 1, 2026
CVE-2026-67106
5.3 MEDIUM

HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker …

Oct 1, 2026
CVE-2026-67104
5.3 MEDIUM

HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the …

Oct 1, 2026
CVE-2026-103347
5.3 MEDIUM

Unauthenticated Bypass Vulnerability in hCaptcha for WP <= 5.3.0 versions.

Oct 1, 2026
CVE-2026-103004
5.3 MEDIUM

Next.js versions from 16.3.0 to 16.3.7 warm `use cache` handlers using `next/root-params` and can leak their return value to pages with different root params. With …

Oct 1, 2026
CVE-2026-66247
4.3 MEDIUM

iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, …

Oct 1, 2026
CVE-2026-102505
6.3 MEDIUM

Imager versions before 1.037 for Perl overflow a heap buffer fetching float samples from a paletted image in i_gsampf_fp. For a paletted image, getsamples() with …

Oct 1, 2026
CVE-2026-62063
5.4 MEDIUM

Missing Authorization vulnerability in Magepeople inc. WpTravelly tour-booking-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WpTravelly: from n/a through 2.3.1.

Oct 1, 2026
CVE-2026-62061
5.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2.

Oct 1, 2026
CVE-2026-62058
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in WPExperts CF7 Apps contact-form-7-honeypot allows Retrieve Embedded Sensitive Data.This issue affects CF7 Apps: from n/a through …

Oct 1, 2026
CVE-2026-103345
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Shamim Rajani Pie Register pie-register allows Retrieve Embedded Sensitive Data.This issue affects Pie Register: from n/a …

Oct 1, 2026
CVE-2026-103343
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP ManageNinja LLC FluentForm fluentform allows Stored XSS.This issue affects FluentForm: from n/a …

Oct 1, 2026
CVE-2026-103341
5.3 MEDIUM

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …

Oct 1, 2026
CVE-2026-103340
5.3 MEDIUM

Missing Authorization vulnerability in Gemini Labs Site Reviews site-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Site Reviews: from n/a through 8.3.2.

Oct 1, 2026
CVE-2026-103339
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet Metform metform allows Stored XSS.This issue affects Metform: from n/a through 4.3.0.

Oct 1, 2026
CVE-2026-103064
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor …

Oct 1, 2026
CVE-2026-103063
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor …

Oct 1, 2026
CVE-2026-102394
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Stored XSS.This issue affects Essential Addons …

Oct 1, 2026
CVE-2026-102390
5.3 MEDIUM

Missing Authorization vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AFFI – Affiliate …

Oct 1, 2026
CVE-2026-102382
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a …

Oct 1, 2026
CVE-2026-102381
5.3 MEDIUM

Missing Authorization vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.

Oct 1, 2026
CVE-2026-103754
5.9 MEDIUM

A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of the ansible-runner transmit/worker …

Oct 1, 2026
CVE-2026-103679
6.5 MEDIUM

A flaw was found in tnef. A remote attacker could exploit this vulnerability by providing a specially crafted Transport Neutral Encapsulation Format (TNEF) file containing …

Oct 1, 2026
CVE-2026-103678
5.4 MEDIUM

A flaw was found in tnef. An attacker can exploit this vulnerability by providing a specially crafted file containing uncompressed Rich Text Format (RTF) data. …

Oct 1, 2026
CVE-2026-103336
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in Smackcoders Inc. WP Ultimate CSV Importer wp-ultimate-csv-importer allows Retrieve Embedded Sensitive Data.This issue affects WP Ultimate …

Oct 1, 2026
CVE-2026-103353
5.3 MEDIUM

Incorrect Behavior Order vulnerability in WP ManageNinja LLC FluentForm fluentform allows Removing Important Client Functionality.This issue affects FluentForm: from n/a through 6.2.14.

Oct 1, 2026
CVE-2026-103291
6.4 MEDIUM

Ghost versions from 3.20.2 before 6.51.0 contain a server-side request forgery vulnerability in image dimension refetching that allows authenticated staff users to trigger outbound HTTP …

Oct 1, 2026
CVE-2026-103289
6.5 MEDIUM

Ghost from 5.9.0 before 6.44.1 contains an input validation issue in the comments feature that allows authenticated members to access comments they are not authorized …

Oct 1, 2026
CVE-2026-103288
6.5 MEDIUM

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can …

Oct 1, 2026
CVE-2026-103285
4.3 MEDIUM

Ghost versions from 5.19.0 before 6.57.1 contain a cross-site request forgery vulnerability in the post feedback functionality that allows attackers to submit feedback on behalf …

Oct 1, 2026
CVE-2026-103284
4.3 MEDIUM

Ghost versions from 5.125.1 before 6.57.1 contain an information disclosure vulnerability in the Admin Feedback endpoint that allows unauthorized staff users to access member data. …

Oct 1, 2026
CVE-2026-103282
4.3 MEDIUM

Ghost versions 0.5.0 before 6.23.0 contain a concurrency issue in the staff invitation acceptance mechanism that allows multiple accounts to be created from a single …

Oct 1, 2026
CVE-2026-103281
5.4 MEDIUM

Ghost (npm package 'ghost') versions from 3.23.0 up to, but not including, 6.23.0 expose API keys to users with low-privilege staff accounts. An authenticated low-privilege …

Oct 1, 2026
CVE-2026-103280
5.3 MEDIUM

Ghost from version 0.8.0 before 6.23.0 contains an information disclosure vulnerability in its setup endpoint: the endpoint responds to unauthenticated requests with the site owner's …

Oct 1, 2026
CVE-2026-103279
6.8 MEDIUM

Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attackers with a stolen session cookie can maintain access …

Oct 1, 2026
CVE-2026-103276
5.3 MEDIUM

Ghost versions before 6.20.0 contain a file extension filtering bypass vulnerability that allows unauthenticated attackers to read theme templates and metadata. Attackers can use URL …

Oct 1, 2026
CVE-2026-103275
4.3 MEDIUM

Ghost 5.42.2 before 6.58.0 contains an information disclosure vulnerability in the Admin API bulk post and page edit and delete endpoints, which accept filters on …

Oct 1, 2026
CVE-2026-103274
5.3 MEDIUM

Ghost versions 5.3.0 before 6.58.0 fail to properly enforce access controls on comments in private mode. Unauthenticated visitors can read comments that should be restricted, …

Oct 1, 2026
CVE-2026-103273
4.3 MEDIUM

Ghost versions 4.3.0 before 6.58.0 contain an authentication bypass vulnerability where lower-privilege staff users can use staff tokens to bypass post editing restrictions. Attackers with …

Oct 1, 2026
CVE-2026-103269
5.3 MEDIUM

Ghost versions 5.3.0 before 6.62.0 contain a missing authorization vulnerability that allows an authenticated site member to read the excerpts of posts they do not …

Oct 1, 2026
CVE-2026-103267
4.3 MEDIUM

Ghost versions before 6.62.0 contain an authentication bypass vulnerability in staff invite acceptance that allows users to specify any email address when creating their account. …

Oct 1, 2026
CVE-2026-103265
4.3 MEDIUM

Fleet versions before 4.89.0 fail to properly filter MDM command results by team authorization in the commands/results endpoint. Team-scoped users can read MDM command results …

Oct 1, 2026
CVE-2026-103263
5.9 MEDIUM

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within …

Oct 1, 2026
CVE-2026-103261
5.3 MEDIUM

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with …

Oct 1, 2026
CVE-2026-103260
4.0 MEDIUM

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can …

Oct 1, 2026
CVE-2026-103258
6.8 MEDIUM

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass …

Oct 1, 2026
CVE-2026-103254
6.3 MEDIUM

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait …

Oct 1, 2026
CVE-2026-103245
5.3 MEDIUM

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook …

Oct 1, 2026
CVE-2026-96256
6.4 MEDIUM

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map …

Oct 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.