CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-62079
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Qi Addons For Elementor <= 1.11 versions.

Sep 30, 2026
CVE-2026-62078
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

Sep 30, 2026
CVE-2026-103117
4.7 MEDIUM

A security vulnerability has been detected in OS4ED openSIS-Classic up to 9.3. Affected is the function db_properties of the file functions/DatabaseInc.php of the component Save …

Sep 30, 2026
CVE-2026-103116
6.3 MEDIUM

A weakness has been identified in OS4ED openSIS-Classic up to 9.3. This impacts the function DBQuery of the file functions/GetStuListFnc.php of the component Student List …

Sep 30, 2026
CVE-2026-103115
6.3 MEDIUM

A security flaw has been discovered in OS4ED openSIS-Classic up to 9.3. This affects an unknown function of the file functions/CustomFieldsFnc.php of the component Student …

Sep 30, 2026
CVE-2026-102399
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Photo Gallery by Supsystic <= 1.21.0 versions.

Sep 30, 2026
CVE-2026-102386
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.

Sep 30, 2026
CVE-2026-102384
5.9 MEDIUM

Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.

Sep 30, 2026
CVE-2026-100513
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in CF7 Views &#8211; Complete Entry Management for Contact Form 7 <= 3.2.5 versions.

Sep 30, 2026
CVE-2026-100508
5.3 MEDIUM

Unauthenticated Denial of Service Attack in Two Factor <= 0.16.0 versions.

Sep 30, 2026
CVE-2026-103114
6.3 MEDIUM

A vulnerability was identified in OS4ED openSIS-Classic up to 9.3. The impacted element is the function DBQuery_assignment of the file modules/grades/Assignments.php of the component Assignment …

Sep 30, 2026
CVE-2026-13720
5.4 MEDIUM

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored …

Sep 30, 2026
CVE-2026-13719
4.3 MEDIUM

An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the …

Sep 30, 2026
CVE-2026-103113
4.7 MEDIUM

A vulnerability was determined in OS4ED openSIS-Classic up to 9.3. The affected element is the function save action of the file modules/students/Student.php of the component …

Sep 30, 2026
CVE-2026-94029
6.5 MEDIUM

Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD …

Sep 30, 2026
CVE-2026-93996
6.5 MEDIUM

Uncontrolled resource consumption in component ssd-scp in Apache MINA SSHD versions up to 2.19.0 or 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library …

Sep 30, 2026
CVE-2026-93995
6.5 MEDIUM

Improper input validation in sshd-git in Apache MINA SSHD, versions up to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for …

Sep 30, 2026
CVE-2026-93908
6.4 MEDIUM

The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all …

Sep 30, 2026
CVE-2026-92712
6.4 MEDIUM

The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'permalink' parameter in all versions up …

Sep 30, 2026
CVE-2026-102588
6.5 MEDIUM

A flaw was found in Moodle. The XML grade import feature lacks proper Cross-Site Request Forgery (CSRF) token validation. By tricking an authenticated user with …

Sep 30, 2026
CVE-2026-102586
4.3 MEDIUM

A flaw was found in Moodle. Insufficient sanitization of username input on the password reset page allows a remote attacker to conduct a cross-site scripting …

Sep 30, 2026
CVE-2026-102585
4.3 MEDIUM

A flaw was found in Moodle. When enrolling a user into a course while assigning them to a group, the application does not verify whether …

Sep 30, 2026
CVE-2026-102584
4.3 MEDIUM

A flaw was found in Moodle. Due to a missing capability check, a low-privileged authenticated user can trigger the recalculation of grade penalties without holding …

Sep 30, 2026
CVE-2026-102581
4.6 MEDIUM

A flaw was found in Moodle. Insufficient output escaping in templates used to display forum posts enables a stored cross-site scripting (XSS) vulnerability. An attacker …

Sep 30, 2026
CVE-2026-102579
4.3 MEDIUM

A flaw was found in Moodle. An incorrect capability check in the grade web service allows an authenticated student to access profile information of other …

Sep 30, 2026
CVE-2026-102578
5.5 MEDIUM

A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, …

Sep 30, 2026
CVE-2026-102577
4.3 MEDIUM

A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass …

Sep 30, 2026
CVE-2026-102459
6.1 MEDIUM

EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.

Sep 30, 2026
CVE-2026-102457
6.5 MEDIUM

EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.

Sep 30, 2026
CVE-2026-102456
6.5 MEDIUM

EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.

Sep 30, 2026
CVE-2025-14564
6.4 MEDIUM

The Viable URL Media Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Sep 30, 2026
CVE-2026-93464
5.4 MEDIUM

A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the …

Sep 30, 2026
CVE-2026-93463
5.4 MEDIUM

A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's …

Sep 30, 2026
CVE-2026-93462
5.3 MEDIUM

A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information.

Sep 30, 2026
CVE-2026-93460
5.4 MEDIUM

A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be …

Sep 30, 2026
CVE-2026-92872
4.3 MEDIUM

Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.

Sep 30, 2026
CVE-2026-92869
6.5 MEDIUM

An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.

Sep 30, 2026
CVE-2026-92868
6.5 MEDIUM

An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.

Sep 30, 2026
CVE-2026-88037
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up …

Sep 30, 2026
CVE-2026-6173
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_image' parameter of the plugin's bt_bb_section shortcode in all versions …

Sep 30, 2026
CVE-2026-6172
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all versions …

Sep 30, 2026
CVE-2026-6171
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' parameter of the plugin's bt_bb_icon shortcode in all versions …

Sep 30, 2026
CVE-2026-6170
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'images' parameter of the plugin's bt_bb_css_image_grid shortcode in all versions …

Sep 30, 2026
CVE-2026-16596
6.5 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to generic SQL Injection via the 'data_fields_list' parameter in all versions up to, and including, 1.5.4 …

Sep 30, 2026
CVE-2026-14876
6.4 MEDIUM

The Smart Slider 3 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data-href' parameter in all versions up to, and including, 3.5.1.38 …

Sep 30, 2026
CVE-2026-11895
6.4 MEDIUM

The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' …

Sep 30, 2026
CVE-2026-97316
5.8 MEDIUM

The Broken Link Notifier WordPress plugin before 2.0.0.1 does not re-validate the destination of redirects when checking links, allowing unauthenticated attackers to bypass its internal-address …

Sep 30, 2026
CVE-2026-96886
5.3 MEDIUM

The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, email address …

Sep 30, 2026
CVE-2026-94274
5.3 MEDIUM

The YayReviews WordPress plugin before 1.4.1 does not restrict access to an API route that returns individual customer review records, including reviews still pending moderation, …

Sep 30, 2026
CVE-2026-93580
5.3 MEDIUM

The InPost PL WordPress plugin before 1.9.8 does not verify the authenticity of incoming shipment webhook requests, relying only on a non-secret identifier and an …

Sep 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.