CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-17531
5.0 MEDIUM

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the …

Jul 27, 2026
CVE-2026-66399
6.5 MEDIUM

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required …

Jul 27, 2026
CVE-2026-17530
6.3 MEDIUM

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of …

Jul 27, 2026
CVE-2026-17529
6.3 MEDIUM

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool …

Jul 27, 2026
CVE-2026-66477
5.3 MEDIUM

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

Jul 27, 2026
CVE-2026-66476
4.9 MEDIUM

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

Jul 27, 2026
CVE-2026-66475
5.9 MEDIUM

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

Jul 27, 2026
CVE-2026-66474
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

Jul 27, 2026
CVE-2026-66448
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

Jul 27, 2026
CVE-2026-66445
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

Jul 27, 2026
CVE-2026-66442
5.4 MEDIUM

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

Jul 27, 2026
CVE-2026-66438
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

Jul 27, 2026
CVE-2026-66437
4.9 MEDIUM

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

Jul 27, 2026
CVE-2026-66434
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

Jul 27, 2026
CVE-2026-66433
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

Jul 27, 2026
CVE-2026-66428
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

Jul 27, 2026
CVE-2026-65568
5.0 MEDIUM

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

Jul 27, 2026
CVE-2026-65567
5.3 MEDIUM

Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 versions.

Jul 27, 2026
CVE-2026-65564
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

Jul 27, 2026
CVE-2026-65563
5.9 MEDIUM

Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.

Jul 27, 2026
CVE-2026-65562
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions.

Jul 27, 2026
CVE-2026-65561
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.0 versions.

Jul 27, 2026
CVE-2026-65558
5.4 MEDIUM

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

Jul 27, 2026
CVE-2026-65557
5.9 MEDIUM

Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.

Jul 27, 2026
CVE-2026-65436
6.8 MEDIUM

Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.

Jul 27, 2026
CVE-2026-65435
6.5 MEDIUM

Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9.2 versions.

Jul 27, 2026
CVE-2026-65434
6.5 MEDIUM

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

Jul 27, 2026
CVE-2026-65433
6.5 MEDIUM

Subscriber Broken Access Control in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

Jul 27, 2026
CVE-2026-59560
6.5 MEDIUM

Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.

Jul 27, 2026
CVE-2026-59559
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg <= 1.5.1 versions.

Jul 27, 2026
CVE-2026-59557
6.5 MEDIUM

Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 versions.

Jul 27, 2026
CVE-2026-10819
6.5 MEDIUM

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file …

Jul 27, 2026
CVE-2026-10600
4.3 MEDIUM

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document …

Jul 27, 2026
CVE-2026-17514
5.3 MEDIUM

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes …

Jul 27, 2026
CVE-2026-15003
5.6 MEDIUM

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted …

Jul 27, 2026
CVE-2026-66053
5.9 MEDIUM

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade …

Jul 27, 2026
CVE-2026-55970
6.5 MEDIUM

Buffer Over-read vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes …

Jul 27, 2026
CVE-2026-17534
5.5 MEDIUM

Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after …

Jul 27, 2026
CVE-2026-66412
6.5 MEDIUM

Leantime 3.6.2 and prior contains a broken access control vulnerability that allows authenticated users to read milestone data from projects they are not assigned to …

Jul 27, 2026
CVE-2026-14827
6.8 MEDIUM

The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field before outputting it inside an HTML attribute on a public-facing page, …

Jul 27, 2026
CVE-2026-14820
5.3 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 11.1.3 does not implement rate limiting or standard failed-login auditing on its front-end credential-check functionality and …

Jul 27, 2026
CVE-2026-14568
6.5 MEDIUM

The User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration WordPress plugin before 4.3.8 does not correctly verify ownership …

Jul 27, 2026
CVE-2026-14236
4.7 MEDIUM

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and …

Jul 27, 2026
CVE-2026-14203
4.8 MEDIUM

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, …

Jul 27, 2026
CVE-2026-14190
6.1 MEDIUM

The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers …

Jul 27, 2026
CVE-2026-13400
6.1 MEDIUM

Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.12.2. The root cause is a sanitization-ordering defect: …

Jul 27, 2026
CVE-2026-13390
5.3 MEDIUM

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips …

Jul 27, 2026
CVE-2026-12982
6.1 MEDIUM

The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user input before reflecting it back in the response of an unauthenticated …

Jul 27, 2026
CVE-2026-10082
6.1 MEDIUM

The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the …

Jul 27, 2026
CVE-2026-17501
5.3 MEDIUM

A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This …

Jul 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.