CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-97262
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.2 versions.

Sep 30, 2026
CVE-2026-97261
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in Notivo <= 1.4.2 versions.

Sep 30, 2026
CVE-2026-97249
5.3 MEDIUM

Unauthenticated Bypass Vulnerability in Paid Member Subscriptions <= 3.0.9 versions.

Sep 30, 2026
CVE-2026-97247
6.5 MEDIUM

Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.

Sep 30, 2026
CVE-2026-97246
4.9 MEDIUM

Subscriber PHP Object Injection in ShortPixel Image Optimizer <= 6.5.5 versions.

Sep 30, 2026
CVE-2026-97243
5.4 MEDIUM

Subscriber Broken Access Control in AllAble Connector <= 0.13.4 versions.

Sep 30, 2026
CVE-2026-97242
6.8 MEDIUM

Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions.

Sep 30, 2026
CVE-2026-97239
6.5 MEDIUM

Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.

Sep 30, 2026
CVE-2026-97238
5.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.

Sep 30, 2026
CVE-2026-97236
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in ThemeREX Addons < 2.45.0 versions.

Sep 30, 2026
CVE-2026-97079
4.3 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Webba Booking <= 6.5.0 versions.

Sep 30, 2026
CVE-2026-97078
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Client Invoicing by Sprout Invoices <= 20.8.17 versions.

Sep 30, 2026
CVE-2026-97074
4.3 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.

Sep 30, 2026
CVE-2026-97067
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.7 versions.

Sep 30, 2026
CVE-2026-97066
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in GiveWP <= 4.16.9 versions.

Sep 30, 2026
CVE-2026-96835
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions.

Sep 30, 2026
CVE-2026-96834
6.5 MEDIUM

Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions.

Sep 30, 2026
CVE-2026-96829
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions.

Sep 30, 2026
CVE-2026-96825
4.2 MEDIUM

Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions.

Sep 30, 2026
CVE-2026-96824
6.8 MEDIUM

Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions.

Sep 30, 2026
CVE-2026-96821
6.3 MEDIUM

Subscriber Privilege Escalation in FluentBoards <= 2.0.12 versions.

Sep 30, 2026
CVE-2026-96450
5.4 MEDIUM

Contributor Cross Site Scripting (XSS) in pixfort Core < 4.3.3 versions.

Sep 30, 2026
CVE-2026-96347
6.5 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Bookly <= 28.2 versions.

Sep 30, 2026
CVE-2026-96338
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.

Sep 30, 2026
CVE-2026-94681
5.9 MEDIUM

Unauthenticated Denial of Service Attack in WP Store Locator < 3.0.0 versions.

Sep 30, 2026
CVE-2026-94674
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions.

Sep 30, 2026
CVE-2026-94673
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Simply Schedule Appointments <= 1.6.12.31 versions.

Sep 30, 2026
CVE-2026-94672
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Safe SVG <= 2.5.0 versions.

Sep 30, 2026
CVE-2026-94173
5.4 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Business Directory <= 6.4.27 versions.

Sep 30, 2026
CVE-2026-94077
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Safe SVG <= 2.5.0 versions.

Sep 30, 2026
CVE-2026-94074
6.5 MEDIUM

Unauthenticated Broken Access Control in Simply Schedule Appointments <= 1.6.12.29 versions.

Sep 30, 2026
CVE-2026-92899
4.8 MEDIUM

Apache WSS4J remembers the Nonce of each UsernameToken it accepts, so a captured token cannot be reused. It stored the Nonce as raw base64 text, …

Sep 30, 2026
CVE-2026-86778
5.3 MEDIUM

Observable response discrepancy vulnerability in Maksisoft Technology, IT, and Software Industry and Trade Inc. Maksisoft Gym allows Account Footprinting. This issue affects Maksisoft Gym: from …

Sep 30, 2026
CVE-2026-62083
5.4 MEDIUM

Subscriber Other Vulnerability Type in Creator LMS <= 1.2.19 versions.

Sep 30, 2026
CVE-2026-62081
5.4 MEDIUM

Contributor Insecure Direct Object References (IDOR) in Flexible PDF Coupons <= 1.14.11 versions.

Sep 30, 2026
CVE-2026-62080
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Happy Addons for Elementor <= 3.23.1 versions.

Sep 30, 2026
CVE-2026-62079
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.

Sep 30, 2026
CVE-2026-62078
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

Sep 30, 2026
CVE-2026-103117
4.7 MEDIUM

A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save …

Sep 30, 2026
CVE-2026-103116
6.3 MEDIUM

A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List …

Sep 30, 2026
CVE-2026-103115
6.3 MEDIUM

A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student …

Sep 30, 2026
CVE-2026-102399
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.

Sep 30, 2026
CVE-2026-102386
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.

Sep 30, 2026
CVE-2026-102384
5.9 MEDIUM

Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.

Sep 30, 2026
CVE-2026-100513
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.

Sep 30, 2026
CVE-2026-100508
5.3 MEDIUM

Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.

Sep 30, 2026
CVE-2026-103114
6.3 MEDIUM

A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment …

Sep 30, 2026
CVE-2026-13720
5.4 MEDIUM

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored …

Sep 30, 2026
CVE-2026-13719
4.3 MEDIUM

An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the …

Sep 30, 2026
CVE-2026-103113
4.7 MEDIUM

A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.