CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-92424
6.8 MEDIUM

The Content Egg WordPress plugin before 11.9.0 does not verify that a user running its bulk content-import feature is authorized for the import preset they …

Sep 30, 2026
CVE-2026-91072
4.4 MEDIUM

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file migration routine to the current site's own uploads directory, letting an …

Sep 30, 2026
CVE-2026-91051
6.6 MEDIUM

The EWWW Image Optimizer WordPress plugin before 8.8.0 does not prevent authenticated users with author-level permissions from storing a serialized value in a post meta …

Sep 30, 2026
CVE-2026-90953
4.3 MEDIUM

The Image Optimizer WordPress plugin before 1.7.7 does not enforce its intended capability check on several of its read REST routes, allowing any authenticated user …

Sep 30, 2026
CVE-2026-89190
4.3 MEDIUM

The Robin Image Optimizer WordPress plugin before 2.0.8 does not check the user's capabilities before dispatching one of its bundled admin framework's request handlers, allowing …

Sep 30, 2026
CVE-2026-87777
6.8 MEDIUM

The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with …

Sep 30, 2026
CVE-2026-86789
5.3 MEDIUM

The Connections Business Directory WordPress plugin through 10.4.67 does not apply its visibility and moderation-status restrictions on certain REST API read endpoints, allowing unauthenticated attackers …

Sep 30, 2026
CVE-2026-85576
4.3 MEDIUM

The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, …

Sep 30, 2026
CVE-2026-85415
6.8 MEDIUM

The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing …

Sep 30, 2026
CVE-2026-85001
6.8 MEDIUM

The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which …

Sep 30, 2026
CVE-2026-83560
5.3 MEDIUM

The New User Approve WordPress plugin before 3.2.10 does not properly verify authentication on a set of integration REST API routes when the integration is …

Sep 30, 2026
CVE-2026-80333
5.3 MEDIUM

The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read …

Sep 30, 2026
CVE-2026-75824
5.3 MEDIUM

The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create …

Sep 30, 2026
CVE-2026-100143
6.5 MEDIUM

The FluentCart A New Era of eCommerce WordPress plugin before 1.6.5 does not verify that the person placing a guest checkout controls the email address …

Sep 30, 2026
CVE-2026-102912
4.7 MEDIUM

A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the …

Sep 30, 2026
CVE-2026-86556
5.3 MEDIUM

There is an information disclosure vulnerability in ZTE U30 Air. Due to improper permission control, attackers can exploit the vulnerability to obtain relevant information.

Sep 30, 2026
CVE-2026-102906
6.3 MEDIUM

A vulnerability was identified in 0xshariq github-mcp-server up to 52e764a7d66eac1726fce02ca7bb5a638571801a. This issue affects the function child_process.exec of the file src/github.ts of the component Git Remove …

Sep 30, 2026
CVE-2026-81310
6.6 MEDIUM

Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log in to a Linux system where the product is installed …

Sep 30, 2026
CVE-2026-78229
6.7 MEDIUM

Image Scanner Driver for Linux contains an OS command injection vulnerability. An attacker who can log in to a Linux system where the affected product …

Sep 30, 2026
CVE-2026-102847
4.3 MEDIUM

A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component …

Sep 30, 2026
CVE-2026-102846
4.7 MEDIUM

A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The …

Sep 30, 2026
CVE-2026-102845
5.3 MEDIUM

A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component …

Sep 30, 2026
CVE-2026-102843
4.7 MEDIUM

A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. …

Sep 30, 2026
CVE-2026-103057
4.3 MEDIUM

AiSOC versions 5.1.0 before 12.0.0 contain an authentication bypass vulnerability in the realtime service internal endpoints POST /internal/agent-event and POST /internal/push. Attackers can post arbitrary …

Sep 30, 2026
CVE-2026-103053
5.4 MEDIUM

AiSOC versions 9.0.0 before 12.0.0 fail to enforce authentication on the response-action API endpoints when AISOC_DEV_MODE is enabled and AISOC_ACTIONS_SERVICE_TOKEN is empty in the default …

Sep 30, 2026
CVE-2026-102842
6.3 MEDIUM

A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component …

Sep 30, 2026
CVE-2026-102805
6.5 MEDIUM

A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. …

Sep 30, 2026
CVE-2026-102804
6.5 MEDIUM

A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of …

Sep 30, 2026
CVE-2026-103051
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects …

Sep 30, 2026
CVE-2026-103050
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS. This issue affects …

Sep 30, 2026
CVE-2026-103049
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo extension allows Reflected XSS. This issue affects …

Sep 30, 2026
CVE-2026-103048
6.1 MEDIUM

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - Collection extension allows Fake the Source of Data. This issue affects …

Sep 30, 2026
CVE-2026-103047
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects …

Sep 29, 2026
CVE-2026-103046
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki …

Sep 29, 2026
CVE-2026-103045
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects …

Sep 29, 2026
CVE-2026-71974
4.8 MEDIUM

U-Boot before 2026.10-rc3 contains an out-of-bounds write vulnerability in read_slotted_partition() that fails to validate image size against partition bounds. Attackers with physical access can supply …

Sep 29, 2026
CVE-2026-71973
5.2 MEDIUM

U-Boot before 2026.10-rc4 contains an integer overflow vulnerability in sqfs_read_directory_table() function when allocating the directory table buffer. Attackers can supply a crafted SquashFS image with …

Sep 29, 2026
CVE-2026-71972
5.9 MEDIUM

U-Boot through 2026.10-rc5 contains an out-of-bounds write vulnerability in the video_display_rle8_bitmap function in drivers/video/video_bmp.c. Attackers can supply a crafted RLE8-compressed BMP image to corrupt memory …

Sep 29, 2026
CVE-2026-102771
4.7 MEDIUM

A security vulnerability has been detected in Naichen ThinkCMF up to 8.0.7. Affected by this issue is the function MailController::templatePut of the file cmf-api/src/admin/controller/MailController.php of …

Sep 29, 2026
CVE-2026-81842
4.3 MEDIUM

An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the …

Sep 29, 2026
CVE-2026-81841
5.3 MEDIUM

Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a …

Sep 29, 2026
CVE-2026-102904
5.4 MEDIUM

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI …

Sep 29, 2026
CVE-2026-79535
6.3 MEDIUM

mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into …

Sep 29, 2026
CVE-2026-79534
5.9 MEDIUM

mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, …

Sep 29, 2026
CVE-2026-79417
5.3 MEDIUM

Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU …

Sep 29, 2026
CVE-2026-79348
4.3 MEDIUM

KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware …

Sep 29, 2026
CVE-2026-76735
4.1 MEDIUM

A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with …

Sep 29, 2026
CVE-2026-76734
4.8 MEDIUM

A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service …

Sep 29, 2026
CVE-2026-76733
4.9 MEDIUM

A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a …

Sep 29, 2026
CVE-2026-76732
6.4 MEDIUM

A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local …

Sep 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.