CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-94029
6.5 MEDIUM

Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD …

Sep 30, 2026
CVE-2026-93996
6.5 MEDIUM

Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library …

Sep 30, 2026
CVE-2026-93995
6.5 MEDIUM

Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for …

Sep 30, 2026
CVE-2026-93908
6.4 MEDIUM

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all …

Sep 30, 2026
CVE-2026-92712
6.4 MEDIUM

The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up …

Sep 30, 2026
CVE-2026-102588
6.5 MEDIUM

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with …

Sep 30, 2026
CVE-2026-102586
4.3 MEDIUM

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting …

Sep 30, 2026
CVE-2026-102585
4.3 MEDIUM

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether …

Sep 30, 2026
CVE-2026-102584
4.3 MEDIUM

A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding …

Sep 30, 2026
CVE-2026-102581
4.6 MEDIUM

A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker …

Sep 30, 2026
CVE-2026-102579
4.3 MEDIUM

A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other …

Sep 30, 2026
CVE-2026-102578
5.5 MEDIUM

A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, …

Sep 30, 2026
CVE-2026-102577
4.3 MEDIUM

A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass …

Sep 30, 2026
CVE-2026-102459
6.1 MEDIUM

EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.

Sep 30, 2026
CVE-2026-102457
6.5 MEDIUM

EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.

Sep 30, 2026
CVE-2026-102456
6.5 MEDIUM

EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.

Sep 30, 2026
CVE-2025-14564
6.4 MEDIUM

The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Sep 30, 2026
CVE-2026-93464
5.4 MEDIUM

A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the …

Sep 30, 2026
CVE-2026-93463
5.4 MEDIUM

A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's …

Sep 30, 2026
CVE-2026-93462
5.3 MEDIUM

A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information.

Sep 30, 2026
CVE-2026-93460
5.4 MEDIUM

A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be …

Sep 30, 2026
CVE-2026-92872
4.3 MEDIUM

Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.

Sep 30, 2026
CVE-2026-92869
6.5 MEDIUM

An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.

Sep 30, 2026
CVE-2026-92868
6.5 MEDIUM

An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.

Sep 30, 2026
CVE-2026-88037
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up …

Sep 30, 2026
CVE-2026-6173
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions …

Sep 30, 2026
CVE-2026-6172
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions …

Sep 30, 2026
CVE-2026-6171
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions …

Sep 30, 2026
CVE-2026-6170
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions …

Sep 30, 2026
CVE-2026-16596
6.5 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 …

Sep 30, 2026
CVE-2026-14876
6.4 MEDIUM

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 …

Sep 30, 2026
CVE-2026-11895
6.4 MEDIUM

The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' …

Sep 30, 2026
CVE-2026-97316
5.8 MEDIUM

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address …

Sep 30, 2026
CVE-2026-96886
5.3 MEDIUM

The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address …

Sep 30, 2026
CVE-2026-94274
5.3 MEDIUM

The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, …

Sep 30, 2026
CVE-2026-93580
5.3 MEDIUM

The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an …

Sep 30, 2026
CVE-2026-92424
6.8 MEDIUM

The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they …

Sep 30, 2026
CVE-2026-91072
4.4 MEDIUM

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an …

Sep 30, 2026
CVE-2026-91051
6.6 MEDIUM

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta …

Sep 30, 2026
CVE-2026-90953
4.3 MEDIUM

The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user …

Sep 30, 2026
CVE-2026-89190
4.3 MEDIUM

The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing …

Sep 30, 2026
CVE-2026-87777
6.8 MEDIUM

The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with …

Sep 30, 2026
CVE-2026-86789
5.3 MEDIUM

The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers …

Sep 30, 2026
CVE-2026-85576
4.3 MEDIUM

The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, …

Sep 30, 2026
CVE-2026-85415
6.8 MEDIUM

The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing …

Sep 30, 2026
CVE-2026-85001
6.8 MEDIUM

The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which …

Sep 30, 2026
CVE-2026-83560
5.3 MEDIUM

The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is …

Sep 30, 2026
CVE-2026-80333
5.3 MEDIUM

The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read …

Sep 30, 2026
CVE-2026-75824
5.3 MEDIUM

The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create …

Sep 30, 2026
CVE-2026-100143
6.5 MEDIUM

The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.