CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-11969
4.9 MEDIUM

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 …

Aug 5, 2026
CVE-2026-11920
4.9 MEDIUM

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter …

Aug 5, 2026
CVE-2026-11454
6.5 MEDIUM

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, …

Aug 5, 2026
CVE-2026-71201
5.0 MEDIUM

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by …

Aug 5, 2026
CVE-2026-68080
6.5 MEDIUM

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive …

Aug 5, 2026
CVE-2026-68078
6.5 MEDIUM

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and …

Aug 5, 2026
CVE-2026-67555
6.5 MEDIUM

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and …

Aug 5, 2026
CVE-2026-67554
6.5 MEDIUM

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial …

Aug 5, 2026
CVE-2026-66277
6.5 MEDIUM

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and …

Aug 5, 2026
CVE-2026-49004
6.5 MEDIUM

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with …

Aug 5, 2026
CVE-2026-17515
4.3 MEDIUM

The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of …

Aug 5, 2026
CVE-2026-16968
6.5 MEDIUM

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access …

Aug 5, 2026
CVE-2026-16942
5.4 MEDIUM

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to …

Aug 5, 2026
CVE-2026-16613
4.3 MEDIUM

The GDPR Cookie Compliance WordPress plugin before 5.1.0 expires the visitor's cookies from an action that is reachable without authentication and performs no request-origin check, …

Aug 5, 2026
CVE-2026-16583
6.1 MEDIUM

The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded SVG files …

Aug 5, 2026
CVE-2026-8790
6.1 MEDIUM

The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up …

Aug 5, 2026
CVE-2026-7753
6.5 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cost-calculator-custom-export-run` AJAX …

Aug 5, 2026
CVE-2026-66839
6.7 MEDIUM

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to …

Aug 5, 2026
CVE-2026-66344
6.7 MEDIUM

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute …

Aug 5, 2026
CVE-2026-5062
4.9 MEDIUM

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' …

Aug 5, 2026
CVE-2026-18903
4.3 MEDIUM

A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument …

Aug 5, 2026
CVE-2026-15941
6.5 MEDIUM

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler …

Aug 5, 2026
CVE-2026-11421
6.5 MEDIUM

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in …

Aug 5, 2026
CVE-2026-18896
6.3 MEDIUM

A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument …

Aug 5, 2026
CVE-2026-18856
4.7 MEDIUM

A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import …

Aug 5, 2026
CVE-2026-45705
5.3 MEDIUM

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs …

Aug 5, 2026
CVE-2026-18853
5.3 MEDIUM

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such …

Aug 5, 2026
CVE-2026-18103
4.9 MEDIUM

A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured …

Aug 5, 2026
CVE-2026-18819
4.3 MEDIUM

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack …

Aug 4, 2026
CVE-2026-18818
6.3 MEDIUM

A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket …

Aug 4, 2026
CVE-2026-70620
6.8 MEDIUM

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying …

Aug 4, 2026
CVE-2026-70594
6.7 MEDIUM

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for …

Aug 4, 2026
CVE-2026-70593
6.6 MEDIUM

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of …

Aug 4, 2026
CVE-2026-70592
5.5 MEDIUM

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database …

Aug 4, 2026
CVE-2026-70591
4.1 MEDIUM

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to …

Aug 4, 2026
CVE-2026-70590
4.8 MEDIUM

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through …

Aug 4, 2026
CVE-2026-70589
4.8 MEDIUM

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer …

Aug 4, 2026
CVE-2026-52370
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the …

Aug 4, 2026
CVE-2026-51144
6.1 MEDIUM

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First …

Aug 4, 2026
CVE-2026-18816
5.0 MEDIUM

A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA …

Aug 4, 2026
CVE-2026-70588
5.0 MEDIUM

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting …

Aug 4, 2026
CVE-2026-70493
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let …

Aug 4, 2026
CVE-2026-70491
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in …

Aug 4, 2026
CVE-2026-70490
6.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message …

Aug 4, 2026
CVE-2026-70489
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules …

Aug 4, 2026
CVE-2026-70488
4.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge …

Aug 4, 2026
CVE-2026-70487
5.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering …

Aug 4, 2026
CVE-2026-54020
6.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, …

Aug 4, 2026
CVE-2026-70484
4.3 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag …

Aug 4, 2026
CVE-2026-70481
5.4 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any …

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.