47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for …
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, …
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful …
apcupsd through 3.14.14 has an sscanf stack-based buffer overflow in getupsvar() in src/cgi/upsfetch.c (used by upsstats.cgi, multimon.cgi, and upsfstats.cgi), a related issue to CVE-2026-15544.
A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order …
A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing …
A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action …
In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted address
In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notification templates
In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPTasty Business Directory business-directory-plugin allows Blind SQL Injection.This issue affects Business …
AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES …
Missing authentication for critical function vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Authentication Bypass. This issue affects Trex MES: through 2026-09-29.
OpenSave through 2.4.0 fails to properly validate save paths supplied by paired peers in the manifest request handler. Attackers can specify arbitrary directories outside configured …
LightLLM through 1.2.0 mounts reinforcement learning control routes on the public HTTP API without authentication checks. Unauthenticated attackers can call endpoints like /pause_generation, /abort_request, /flush_cache, …
MQTT WebSocket setter ABI mismatch may disclose memory or cause a crash
Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the …
Contributor SQL Injection in Media LIbrary Assistant <= 3.41 versions.
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP Event Tickets event-tickets allows Blind SQL Injection.This …
Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions.
Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kreatura LayerSlider allows Reflected XSS. This issue affects LayerSlider: from n/a through 8.4.0.
Unauthenticated Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Shop Worker Privilege Escalation in SureCart <= 4.7.2 versions.
Contributor Path Traversal in Creator LMS <= 1.2.19 versions.
Unauthenticated Sensitive Data Exposure in BackupEase <= 2.2.2 versions.
Unauthenticated Sensitive Data Exposure in StifLi Backup Tools <= 2.2.7 versions.
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
Unauthenticated Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.
Unauthenticated Broken Access Control in WordPress Backup & Migration <= 1.6.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Ad Inserter <= 2.8.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions.
Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions.
Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions.
Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions.
Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions.
Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions.
Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions.
Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions.
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
Free website and port scanning — find vulnerabilities before attackers do.