CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-83589
6.1 MEDIUM

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit …

Oct 1, 2026
CVE-2026-103497
5.5 MEDIUM

In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration

Oct 1, 2026
CVE-2026-103496
5.4 MEDIUM

In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications

Oct 1, 2026
CVE-2026-103495
4.3 MEDIUM

In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs

Oct 1, 2026
CVE-2026-103494
6.6 MEDIUM

In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes

Oct 1, 2026
CVE-2026-103492
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments

Oct 1, 2026
CVE-2026-103491
6.5 MEDIUM

In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues

Oct 1, 2026
CVE-2026-96268
6.4 MEDIUM

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions …

Oct 1, 2026
CVE-2026-90992
6.4 MEDIUM

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User Meta Merge via 'user-mediaurl' Media Field in all versions up to, …

Oct 1, 2026
CVE-2026-89427
6.1 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions …

Oct 1, 2026
CVE-2026-89424
6.4 MEDIUM

The Duplicate Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'noti_token' parameter in all versions up to, and including, 1.5.6 due …

Oct 1, 2026
CVE-2026-101925
6.4 MEDIUM

The bbp style pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'display_name (via /wp-admin/profile.php) + bbp_reply_content (via bbPress reply form)' parameter …

Oct 1, 2026
CVE-2026-100184
4.7 MEDIUM

The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based …

Oct 1, 2026
CVE-2026-100179
6.1 MEDIUM

The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is vulnerable to Reflected DOM-Based …

Oct 1, 2026
CVE-2026-89047
6.1 MEDIUM

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, …

Oct 1, 2026
CVE-2026-19902
6.1 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Referer header in all versions …

Oct 1, 2026
CVE-2026-103544
6.3 MEDIUM

A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al …

Oct 1, 2026
CVE-2026-96200
5.3 MEDIUM

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that payment notifications received by its payment callback come from the payment provider, allowing …

Oct 1, 2026
CVE-2026-96173
5.3 MEDIUM

The Payments for Hubtel WordPress plugin before 1.0.2 does not verify that the requester is authorized to view an order before redirecting a public payment-callback …

Oct 1, 2026
CVE-2026-90974
6.5 MEDIUM

The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to …

Oct 1, 2026
CVE-2026-90972
5.4 MEDIUM

The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber …

Oct 1, 2026
CVE-2026-88999
4.3 MEDIUM

The Redux Framework plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.14 This is due to the plugin …

Oct 1, 2026
CVE-2026-87970
4.7 MEDIUM

The If-So Dynamic Content WordPress plugin before 1.10.2 does not escape a request-supplied value before reflecting it in an unauthenticated AJAX response that is served …

Oct 1, 2026
CVE-2026-86610
6.4 MEDIUM

The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could …

Oct 1, 2026
CVE-2026-67075
6.5 MEDIUM

HCL Digital Experience is affected by improper input sanitation. This can result in HTML injection which could be leveraged in content spoofing from a trusted …

Oct 1, 2026
CVE-2026-103543
6.3 MEDIUM

A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of …

Oct 1, 2026
CVE-2026-103542
4.3 MEDIUM

A flaw has been found in formtools.org Form Tools up to 3.1.1. Impacted is the function smart_fill of the file /global/code/actions.php of the component AJAX …

Oct 1, 2026
CVE-2026-103541
6.3 MEDIUM

A vulnerability was detected in formtools.org Form Tools up to 3.1.1. This issue affects the function Files::uploadFile of the file global/code/actions.php of the component Ajax …

Oct 1, 2026
CVE-2026-103540
6.3 MEDIUM

A security vulnerability has been detected in formtools.org Form Tools up to 3.1.1. This vulnerability affects the function Clients::updateClientSettingsTab of the file global/code/Clients.class.php of the …

Oct 1, 2026
CVE-2026-92548
5.3 MEDIUM

The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' parameter. …

Oct 1, 2026
CVE-2026-12241
5.4 MEDIUM

The Advanced Woo Labels – Product Labels & Badges for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improperly …

Oct 1, 2026
CVE-2026-103539
5.4 MEDIUM

A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a …

Oct 1, 2026
CVE-2026-103538
6.5 MEDIUM

A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component …

Oct 1, 2026
CVE-2026-91109
6.5 MEDIUM

The Simply Schedule Appointments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.6.12.31 via the 'complete_group' …

Oct 1, 2026
CVE-2026-103641
5.5 MEDIUM

A flaw was found in GEGL. The Radiance HDR loader reads past the end of a memory-mapped image when an uncompressed scanline is shorter than …

Oct 1, 2026
CVE-2026-103534
6.3 MEDIUM

A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This …

Oct 1, 2026
CVE-2026-92537
5.3 MEDIUM

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Insufficiently Protected Credentials in all versions up to, and including, 9.3.9 …

Oct 1, 2026
CVE-2026-103533
4.1 MEDIUM

A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. …

Oct 1, 2026
CVE-2026-103532
5.3 MEDIUM

A vulnerability has been found in immich-app Immich up to 2.7.5. This affects the function checkSharedLinkAccess of the file server/src/utils/access.ts of the component Shared Link …

Oct 1, 2026
CVE-2026-103531
5.5 MEDIUM

A flaw has been found in OpenSC up to 0.27.1. The impacted element is the function setcos_construct_fci_44 of the file src/libopensc/card-setcos.c. Executing a manipulation of …

Oct 1, 2026
CVE-2026-103592
6.5 MEDIUM

simple-php-router through 5.4.1.7 contains an IP restriction bypass vulnerability in the IpRestrictAccess middleware that allows remote unauthenticated attackers to bypass IP whitelist and blacklist protections. …

Sep 30, 2026
CVE-2026-103590
5.4 MEDIUM

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to …

Sep 30, 2026
CVE-2026-103589
5.4 MEDIUM

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values …

Sep 30, 2026
CVE-2026-103588
5.4 MEDIUM

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious …

Sep 30, 2026
CVE-2026-103587
5.4 MEDIUM

QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied …

Sep 30, 2026
CVE-2026-47096
6.1 MEDIUM

AJA HELO Plus firmware before 2.1.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers with network access to inject malicious JavaScript by setting …

Sep 30, 2026
CVE-2026-103001
6.5 MEDIUM

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when …

Sep 30, 2026
CVE-2026-102146
6.5 MEDIUM

An authenticated Email Protection Gateway administrator holding only limited, delegated permissions could write files with attacker-controlled content to arbitrary locations accessible to the Email Protection …

Sep 30, 2026
CVE-2026-102145
6.6 MEDIUM

An authenticated administrator could cause the server to issue requests to, and interact with, internal network services that are not meant to be reachable through …

Sep 30, 2026
CVE-2026-102144
5.3 MEDIUM

A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.