CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18203
6.5 MEDIUM

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to …

Jul 31, 2026
CVE-2026-16105
4.9 MEDIUM

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly …

Jul 31, 2026
CVE-2026-8155
5.4 MEDIUM

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated user (Subscriber+) to read, modify, or …

Jul 31, 2026
CVE-2026-18452
10.0 CRITICAL

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control …

Jul 31, 2026
CVE-2026-16236
8.8 HIGH

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing …

Jul 31, 2026
CVE-2026-15381
3.7 LOW

The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated …

Jul 31, 2026
CVE-2026-15258
8.1 HIGH

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a …

Jul 31, 2026
CVE-2026-15209
6.5 MEDIUM

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can …

Jul 31, 2026
CVE-2026-15048
7.5 HIGH

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history …

Jul 31, 2026
CVE-2026-14931
6.5 MEDIUM

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check …

Jul 31, 2026
CVE-2026-14930
7.5 HIGH

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users …

Jul 31, 2026
CVE-2026-14929
4.3 MEDIUM

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and …

Jul 31, 2026
CVE-2026-14928
6.5 MEDIUM

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing …

Jul 31, 2026
CVE-2026-14927
3.7 LOW

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed …

Jul 31, 2026
CVE-2026-14922
6.1 MEDIUM

WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the …

Jul 31, 2026
CVE-2026-14921
6.1 MEDIUM

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(),

Jul 31, 2026
CVE-2026-14919
9.8 CRITICAL

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied …

Jul 31, 2026
CVE-2026-14862
3.7 LOW

The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file …

Jul 31, 2026
CVE-2026-14849
3.7 LOW

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it writes to a predictable location in the …

Jul 31, 2026
CVE-2026-14847
4.3 MEDIUM

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not perform capability or nonce checks on one of its payment-related AJAX actions, allowing any authenticated …

Jul 31, 2026
CVE-2026-14845
6.1 MEDIUM

The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in …

Jul 31, 2026
CVE-2026-14843
5.3 MEDIUM

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an unauthenticated …

Jul 31, 2026
CVE-2026-14834
6.5 MEDIUM

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the …

Jul 31, 2026
CVE-2026-14833
6.8 MEDIUM

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image lightbox caption …

Jul 31, 2026
CVE-2026-14830
7.5 HIGH

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order …

Jul 31, 2026
CVE-2026-14554
6.5 MEDIUM

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with …

Jul 31, 2026
CVE-2026-14483
9.8 CRITICAL

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, …

Jul 31, 2026
CVE-2026-14333
7.5 HIGH

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing …

Jul 31, 2026
CVE-2026-14319
7.5 HIGH

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve …

Jul 31, 2026
CVE-2026-14317
5.3 MEDIUM

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it in part …

Jul 31, 2026
CVE-2026-13609
8.8 HIGH

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags …

Jul 31, 2026
CVE-2026-13393
3.5 LOW

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the …

Jul 31, 2026
CVE-2026-13392
7.2 HIGH

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim …

Jul 31, 2026
CVE-2026-12721
8.6 HIGH

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, …

Jul 31, 2026
CVE-2026-12720
7.5 HIGH

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to …

Jul 31, 2026
CVE-2026-12697
5.4 MEDIUM

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messages, allowing …

Jul 31, 2026
CVE-2026-12695
8.1 HIGH

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an …

Jul 31, 2026
CVE-2026-12376
4.3 MEDIUM

The Academy LMS WordPress plugin through 3.8.2 does not restrict access to quiz attempt records to their owner, allowing any authenticated user with subscriber-level access …

Jul 31, 2026
CVE-2026-12251
8.1 HIGH

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration …

Jul 31, 2026
CVE-2026-63223
9.8 CRITICAL

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename …

Jul 31, 2026
CVE-2026-63222
7.5 HIGH

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote …

Jul 31, 2026
CVE-2026-63221
9.4 CRITICAL

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring …

Jul 31, 2026
CVE-2026-56673
7.5 HIGH

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to …

Jul 31, 2026
CVE-2026-56672
8.2 HIGH

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, …

Jul 31, 2026
CVE-2026-56671
7.5 HIGH

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route …

Jul 31, 2026
CVE-2026-56670
8.2 HIGH

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline …

Jul 31, 2026
CVE-2026-63220
4.8 MEDIUM

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an …

Jul 31, 2026
CVE-2026-62323
6.3 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does …

Jul 31, 2026
CVE-2026-55502
7.1 HIGH

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and …

Jul 31, 2026
CVE-2026-55499
4.3 MEDIUM

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent …

Jul 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.