CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-96819
7.1 HIGH

Subscriber Cross Site Scripting (XSS) in oik <= 4.15.4 versions.

Sep 30, 2026
CVE-2026-96818
7.5 HIGH

Unauthenticated Broken Access Control in WP Express Checkout (Accept PayPal Payments) <= 2.4.9 versions.

Sep 30, 2026
CVE-2026-96817
8.2 HIGH

Subscriber Broken Access Control in MakeCommerce for WooCommerce <= 4.1.0 versions.

Sep 30, 2026
CVE-2026-96816
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Trusted Shops Easy Integration for WooCommerce <= 2.0.6 versions.

Sep 30, 2026
CVE-2026-96815
7.2 HIGH

Custom role Privilege Escalation in Vitepos <= 3.5.0 versions.

Sep 30, 2026
CVE-2026-96814
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.

Sep 30, 2026
CVE-2026-96352
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in YITH WooCommerce Ajax Search <= 2.28.0 versions.

Sep 30, 2026
CVE-2026-96351
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 6.1.3 versions.

Sep 30, 2026
CVE-2026-96348
7.5 HIGH

Unauthenticated Broken Access Control in Bookly <= 28.2 versions.

Sep 30, 2026
CVE-2026-96346
7.6 HIGH

Author SQL Injection in WP ERP <= 1.17.9 versions.

Sep 30, 2026
CVE-2026-96345
7.6 HIGH

Administrator SQL Injection in Estatik <= 4.3.5 versions.

Sep 30, 2026
CVE-2026-96344
7.2 HIGH

Custom role PHP Object Injection in eCommerce Product Catalog <= 3.6.0 versions.

Sep 30, 2026
CVE-2026-96343
7.2 HIGH

Custom role PHP Object Injection in WP ERP <= 1.17.9 versions.

Sep 30, 2026
CVE-2026-95616
7.5 HIGH

An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 …

Sep 30, 2026
CVE-2026-95587
7.5 HIGH

Unauthenticated Broken Access Control in Hostinger Migrator <= 1.0 versions.

Sep 30, 2026
CVE-2026-95531
8.8 HIGH

Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.

Sep 30, 2026
CVE-2026-94683
8.8 HIGH

Contributor PHP Object Injection in DesignSetGo <= 2.8.0 versions.

Sep 30, 2026
CVE-2026-94678
8.8 HIGH

Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions.

Sep 30, 2026
CVE-2026-94677
7.2 HIGH

Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions.

Sep 30, 2026
CVE-2026-94499
7.1 HIGH

Subscriber Broken Access Control in FormGent <= 1.12.2 versions.

Sep 30, 2026
CVE-2026-94178
7.5 HIGH

Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.

Sep 30, 2026
CVE-2026-94177
8.5 HIGH

Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.

Sep 30, 2026
CVE-2026-94123
7.5 HIGH

Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.

Sep 30, 2026
CVE-2026-94122
7.2 HIGH

Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.

Sep 30, 2026
CVE-2026-94121
8.8 HIGH

Contributor PHP Object Injection in 10Web Booster – Website speed optimization, Cache & Page Speed optimizer <= 2.33.6 versions.

Sep 30, 2026
CVE-2026-94120
7.5 HIGH

Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.

Sep 30, 2026
CVE-2026-94115
8.5 HIGH

Contributor SQL Injection in Easy Pricing Tables <= 4.1.2 versions.

Sep 30, 2026
CVE-2026-94082
7.6 HIGH

Author SQL Injection in Quiz Cat <= 3.1.1 versions.

Sep 30, 2026
CVE-2026-94081
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WordPress Persistent Login <= 3.1.3 versions.

Sep 30, 2026
CVE-2026-94078
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.3.1 versions.

Sep 30, 2026
CVE-2026-94076
8.8 HIGH

Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.

Sep 30, 2026
CVE-2026-93771
7.2 HIGH

Shop manager PHP Object Injection in Cost of Goods for WooCommerce <= 3.5.2 versions.

Sep 30, 2026
CVE-2026-93770
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.

Sep 30, 2026
CVE-2026-93651
7.2 HIGH

Author PHP Object Injection in Minimum and Maximum Quantity for WooCommerce <= 2.1.2 versions.

Sep 30, 2026
CVE-2026-93624
7.2 HIGH

Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.

Sep 30, 2026
CVE-2026-93621
8.2 HIGH

Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions.

Sep 30, 2026
CVE-2026-93514
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Notification for Telegram <= 3.5.2 versions.

Sep 30, 2026
CVE-2026-93512
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.

Sep 30, 2026
CVE-2026-92121
7.5 HIGH

In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer …

Sep 30, 2026
CVE-2026-62085
7.6 HIGH

Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.

Sep 30, 2026
CVE-2026-27371
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPFunnels <= 3.13.1 versions.

Sep 30, 2026
CVE-2026-102398
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.

Sep 30, 2026
CVE-2026-102396
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Ultimate Maps by Supsystic <= 1.5.5 versions.

Sep 30, 2026
CVE-2026-102395
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Easy Google Maps <= 1.14.6 versions.

Sep 30, 2026
CVE-2026-102385
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.

Sep 30, 2026
CVE-2026-100507
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in If-So Dynamic Content Personalization <= 1.10.1 versions.

Sep 30, 2026
CVE-2026-85532
7.5 HIGH

Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds. This could permit cryptographically weak keys or excessive CPU and memory consumption when processing …

Sep 30, 2026
CVE-2026-62146
7.8 HIGH

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a …

Sep 30, 2026
CVE-2026-103242
7.1 HIGH

A heap-based buffer overflow flaw was found in rpm. RPMTAG_FILESIGNATURES in a crafted, unsigned RPM package's main header is declared with the wrong header type, …

Sep 30, 2026
CVE-2026-76992
7.5 HIGH

The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.