CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-28040
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi …

Apr 23, 2026
CVE-2025-62110
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a …

Apr 23, 2026
CVE-2025-62104
4.3 MEDIUM

Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through …

Apr 23, 2026
CVE-2026-3960
5.9 MEDIUM

A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/ImportSQLTable in H2O-3 version 3.46.0.9 and prior. The vulnerability arises due to …

Apr 23, 2026
CVE-2026-4106
5.3 MEDIUM

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and …

Apr 23, 2026
CVE-2025-10549
5.1 MEDIUM

EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially …

Apr 23, 2026
CVE-2026-41990
4.0 MEDIUM

Libgcrypt before 1.12.2 mishandles Dilithium signing. Writes to a static array lack a bounds check but do not use attacker-controlled data.

Apr 23, 2026
CVE-2026-41989
6.7 MEDIUM

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

Apr 23, 2026
CVE-2026-41233
5.4 MEDIUM

Froxlor is open source server administration software. Prior to version 2.3.6, in `Domains.add()`, the `adminid` parameter is accepted from user input and used without validation …

Apr 23, 2026
CVE-2026-41232
5.0 MEDIUM

Froxlor is open source server administration software. Prior to version 2.3.6, in `EmailSender::add()`, the domain ownership validation for full email sender aliases uses the wrong …

Apr 23, 2026
CVE-2026-40529
4.7 MEDIUM

CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with …

Apr 23, 2026
CVE-2026-3361
6.4 MEDIUM

The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpsl_address' post meta value in versions up to, and including, …

Apr 23, 2026
CVE-2026-3007
5.4 MEDIUM

Successful exploitation of the stored cross-site scripting (XSS) vulnerability could allow an attacker to execute arbitrary JavaScript on any user account that has access to …

Apr 23, 2026
CVE-2026-2951
5.4 MEDIUM

The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and …

Apr 23, 2026
CVE-2026-41243
5.4 MEDIUM

OpenLearn is open-source educational forum software. Prior to commit 844b2a40a69d0c4911580fe501923f0b391313ab, when `safeMode` is enabled, unapproved forum posts are hidden from the public list, but the …

Apr 23, 2026
CVE-2026-41182
5.3 MEDIUM

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python …

Apr 23, 2026
CVE-2026-1923
6.4 MEDIUM

The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, …

Apr 23, 2026
CVE-2026-6878
5.6 MEDIUM

A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. …

Apr 23, 2026
CVE-2026-6874
4.3 MEDIUM

A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token of the component Header Handler. Executing …

Apr 23, 2026
CVE-2026-5926
6.5 MEDIUM

IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 …

Apr 23, 2026
CVE-2026-4919
4.8 MEDIUM

IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web UI …

Apr 23, 2026
CVE-2026-4918
5.5 MEDIUM

IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrative user to embed arbitrary JavaScript code in the Web …

Apr 23, 2026
CVE-2026-4917
4.9 MEDIUM

IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker could send a specially crafted URL request …

Apr 23, 2026
CVE-2026-1726
4.8 MEDIUM

IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1

Apr 23, 2026
CVE-2026-1352
6.5 MEDIUM

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow an authenticated user to cause …

Apr 23, 2026
CVE-2026-1274
4.9 MEDIUM

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access management control panel.

Apr 23, 2026
CVE-2025-36074
5.5 MEDIUM

IBM Security Verify Directory (Container) 10.0.0 through 10.0.0.3 IBM Security Verify Directory could be vulnerable to malicious file upload by not validating file type. A …

Apr 23, 2026
CVE-2026-41314
6.5 MEDIUM

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF …

Apr 22, 2026
CVE-2026-41313
6.5 MEDIUM

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF …

Apr 22, 2026
CVE-2026-41312
6.5 MEDIUM

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.2 can craft a PDF …

Apr 22, 2026
CVE-2026-41177
5.5 MEDIUM

Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind …

Apr 22, 2026
CVE-2026-41168
5.3 MEDIUM

pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior to 6.10.1 can craft a PDF …

Apr 22, 2026
CVE-2026-3837
5.4 MEDIUM

An authenticated attacker can persist crafted values in multiple field types and trigger client-side script execution when another user opens the affected document in Desk. …

Apr 22, 2026
CVE-2026-34068
6.8 MEDIUM

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, the staking contract accepts `UpdateValidator` transactions that set `new_voting_key=Some(...)` …

Apr 22, 2026
CVE-2026-3673
5.4 MEDIUM

An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript execution when a victim opens the list/report view where tags are …

Apr 22, 2026
CVE-2026-34066
5.3 MEDIUM

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStore::put_historic_txns` uses an `assert!` to enforce invariants about `HistoricTransaction.block_number` (must be within …

Apr 22, 2026
CVE-2026-34064
5.3 MEDIUM

nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_balance < min_cap`, but it constructs …

Apr 22, 2026
CVE-2026-34062
5.3 MEDIUM

nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer …

Apr 22, 2026
CVE-2026-41469
5.2 MEDIUM

Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template …

Apr 22, 2026
CVE-2026-41459
5.3 MEDIUM

Xerte Online Toolkits versions 3.15 and earlier contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the full server-side filesystem path of the …

Apr 22, 2026
CVE-2026-28950
6.2 MEDIUM

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS …

Apr 22, 2026
CVE-2026-6515
5.4 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have …

Apr 22, 2026
CVE-2026-5377
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles …

Apr 22, 2026
CVE-2026-35380
5.5 MEDIUM

A logic error in the cut utility of uutils coreutils causes the program to incorrectly interpret the literal two-byte string '' (two single quotes) as …

Apr 22, 2026
CVE-2026-35376
4.5 MEDIUM

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the chcon utility of uutils coreutils during recursive operations. The implementation resolves recursive targets using a fresh …

Apr 22, 2026
CVE-2026-35374
6.3 MEDIUM

A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the split utility of uutils coreutils. The program attempts to prevent data loss by checking for identity …

Apr 22, 2026
CVE-2026-35372
5.0 MEDIUM

A logic error in the ln utility of uutils coreutils allows the utility to dereference a symbolic link target even when the --no-dereference (or -n) …

Apr 22, 2026
CVE-2026-35370
4.4 MEDIUM

The id utility in uutils coreutils miscalculates the groups= section of its output. The implementation uses a user's real GID instead of their effective GID …

Apr 22, 2026
CVE-2026-35369
5.5 MEDIUM

An argument parsing error in the kill utility of uutils coreutils incorrectly interprets kill -1 as a request to send the default signal (SIGTERM) to …

Apr 22, 2026
CVE-2026-35366
4.4 MEDIUM

The printenv utility in uutils coreutils fails to display environment variables containing invalid UTF-8 byte sequences. While POSIX permits arbitrary bytes in environment strings, the …

Apr 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.