CVE Database

4751+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14862
3.7 LOW

The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file …

Jul 31, 2026
CVE-2026-14849
3.7 LOW

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the …

Jul 31, 2026
CVE-2026-13393
3.5 LOW

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the …

Jul 31, 2026
CVE-2026-58039
3.3 LOW

A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of …

Jul 31, 2026
CVE-2026-41709
2.7 LOW

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

Jul 30, 2026
CVE-2026-59326
3.3 LOW

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and …

Jul 30, 2026
CVE-2026-56847
3.3 LOW

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended …

Jul 30, 2026
CVE-2026-15054
3.7 LOW

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submission handlers, allowing unauthenticated users to submit entries …

Jul 30, 2026
CVE-2026-14222
3.8 LOW

The Easy Appointments WordPress plugin through 3.12.26 does not perform any capability or nonce check in one of its connection-deletion actions, allowing users with contributor-level …

Jul 30, 2026
CVE-2026-14221
3.8 LOW

The Easy Appointments WordPress plugin through 3.12.26 does not perform capability checks in several of its appointment-management actions, relying only on a nonce that any …

Jul 30, 2026
CVE-2026-14188
2.7 LOW

The Easy Appointments WordPress plugin through 3.12.26 does not perform a per-request capability or nonce check on one of its customer-listing handlers, allowing authenticated users …

Jul 30, 2026
CVE-2026-18011
2.4 LOW

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process …

Jul 30, 2026
CVE-2026-18000
3.1 LOW

Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak …

Jul 30, 2026
CVE-2026-17997
3.1 LOW

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Jul 30, 2026
CVE-2026-17984
3.3 LOW

Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. …

Jul 30, 2026
CVE-2026-17980
3.1 LOW

Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI …

Jul 30, 2026
CVE-2026-17957
3.1 LOW

Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Jul 30, 2026
CVE-2026-17902
3.5 LOW

Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. …

Jul 30, 2026
CVE-2026-17860
3.3 LOW

Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof the contents of the …

Jul 30, 2026
CVE-2026-17826
3.1 LOW

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in …

Jul 30, 2026
CVE-2026-17766
3.3 LOW

Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a …

Jul 30, 2026
CVE-2026-17732
3.1 LOW

Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Jul 30, 2026
CVE-2026-17720
3.1 LOW

Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data …

Jul 30, 2026
CVE-2026-17715
3.1 LOW

Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Jul 30, 2026
CVE-2026-17702
3.1 LOW

Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

Jul 30, 2026
CVE-2025-14562
3.1 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain …

Jul 29, 2026
CVE-2026-2482
3.1 LOW

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized …

Jul 29, 2026
CVE-2026-10684
3.0 LOW

In subsys/debug/coredump/coredump_shell.c, print_coredump_hdr() used the 16-bit tgt_code field of a stored Zephyr coredump header directly as an index into coredump_target_code2str[], a fixed 7-element array of …

Jul 29, 2026
CVE-2026-58187
3.7 LOW

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 …

Jul 29, 2026
CVE-2026-63241
3.1 LOW

An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course completion progress of any other user without authorisation, …

Jul 29, 2026
CVE-2026-63236
3.7 LOW

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name, internal identifier, scores, lesson status, lesson position, and …

Jul 29, 2026
CVE-2026-63235
3.7 LOW

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the session of any user given their email address via …

Jul 29, 2026
CVE-2026-63228
2.6 LOW

An unrestricted image upload vulnerability in Koollab LMS allowed an authenticated attacker to upload malicious content disguised as an image file via the feedback mail …

Jul 29, 2026
CVE-2026-55403
3.7 LOW

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_generator/http.py get_body reuses Authorization, Cookie, and Proxy-Authorization headers when following cross-origin redirects while fetching …

Jul 28, 2026
CVE-2026-66753
3.7 LOW

tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header …

Jul 28, 2026
CVE-2026-17072
3.3 LOW

A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of-bounds read of 4 bytes can occur when parsing FLAC audio stream headers embedded in a …

Jul 28, 2026
CVE-2026-55977
3.3 LOW

Successful exploitation of this vulnerability could allow an attacker with local network access to bypass the application's rate-limiting mechanism, enabling brute-forcing of the screen-sharing code …

Jul 28, 2026
CVE-2026-14821
2.7 LOW

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates, allowing users with contributor-level access …

Jul 28, 2026
CVE-2026-14819
3.5 LOW

The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ticket history log, allowing users …

Jul 28, 2026
CVE-2026-64745
2.4 LOW

This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with …

Jul 27, 2026
CVE-2026-10683
2.4 LOW

In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating in target/slave mode, the rx_full interrupt handler gates the write_requested() callback on dw->state != CMD_SEND, and dw->state …

Jul 27, 2026
CVE-2026-48051
3.5 LOW

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, Papra's webhook delivery system contains an SSRF protection bypass that allows any …

Jul 27, 2026
CVE-2026-17513
3.3 LOW

A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected is the function ggml_ftype_to_ggml_type of the file ggml/src/ggml.c. The manipulation of the argument ftype results in …

Jul 27, 2026
CVE-2026-56538
3.5 LOW

An endpoint in HCL Connections is vulnerable to information disclosure. In certain scenarios this might lead to disclosing sensitive information to unauthorized users.

Jul 27, 2026
CVE-2026-56537
3.5 LOW

HCL Connections is vulnerable to information disclosure which could allow a user to obtain sensitive information they are not entitled to, caused by improper handling …

Jul 27, 2026
CVE-2026-17512
3.3 LOW

A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This impacts the function log_mel_spectrogram of the file src/whisper.cpp. The manipulation leads to out-of-bounds read. The …

Jul 27, 2026
CVE-2026-40000
1.8 LOW

The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., …

Jul 27, 2026
CVE-2026-14189
3.8 LOW

The WPBot WordPress plugin before 8.5.2 does not validate administrator-configured field identifiers before using them in a SQL query, allowing users with administrator access to …

Jul 27, 2026
CVE-2026-66011
3.3 LOW

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly …

Jul 25, 2026
CVE-2026-17039
3.1 LOW

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, …

Jul 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.