CVE Database

60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-27434
5.3 MEDIUM

Missing Authorization vulnerability in sc Internet Vivoo WP Rentals wprentals allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rentals: from n/a through …

Oct 7, 2026
CVE-2026-105884
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows Stored XSS.This issue affects Rocket Lazy …

Oct 7, 2026
CVE-2026-105876
5.3 MEDIUM

Missing Authorization vulnerability in WP Chill Modula Image Gallery modula-best-grid-gallery allows Retrieve Embedded Sensitive Data.This issue affects Modula Image Gallery: from n/a through 3.0.11.

Oct 7, 2026
CVE-2026-105875
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor bdthemes-prime-slider-lite allows Stored XSS.This issue affects …

Oct 7, 2026
CVE-2026-105873
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack …

Oct 7, 2026
CVE-2026-105871
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-element-pack-lite allows Stored XSS.This issue affects Element Pack …

Oct 7, 2026
CVE-2026-104393
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs Happy Addons for Elementor happy-elementor-addons allows Stored XSS.This issue affects Happy Addons …

Oct 7, 2026
CVE-2026-104391
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Stored XSS.This issue affects Quiz And …

Oct 7, 2026
CVE-2026-104390
4.3 MEDIUM

Missing Authorization vulnerability in Arraytics Booktics booktics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booktics: from n/a through 1.0.27.

Oct 7, 2026
CVE-2026-103075
4.3 MEDIUM

Missing Authorization vulnerability in WPMU DEV Hustle wordpress-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hustle: from n/a through 7.8.14.2.

Oct 7, 2026
CVE-2026-93684
5.4 MEDIUM

An SQL user using Impala up to and including version 4.5.2 with only SELECT permission can put JavaScript in a table alias and make it …

Oct 7, 2026
CVE-2026-90466
6.5 MEDIUM

Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified …

Oct 7, 2026
CVE-2026-107121
6.5 MEDIUM

A flaw was found in the SMTP email configuration handling of the keycloak-services component. When the STARTTLS option is enabled, Keycloak fails to strictly enforce …

Oct 7, 2026
CVE-2026-97354
4.1 MEDIUM

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.11 does not validate the destination of redirects when fetching a user-supplied media URL, allowing users …

Oct 7, 2026
CVE-2026-97331
4.3 MEDIUM

The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that …

Oct 7, 2026
CVE-2026-96530
6.5 MEDIUM

The Optimole WordPress plugin before 4.2.15 does not perform a capability check before exposing its stored image-optimization account data in a dashboard widget, allowing any …

Oct 7, 2026
CVE-2026-86833
5.4 MEDIUM

The MetForm WordPress plugin before 4.3.1 does not sanitize or escape submitted form-field values before inserting them into the HTML body of its email notifications, …

Oct 7, 2026
CVE-2026-86816
5.3 MEDIUM

The WPCafe WordPress plugin before 3.0.21 does not restrict access to some of its REST API endpoints, allowing unauthenticated attackers to read WooCommerce product data, …

Oct 7, 2026
CVE-2026-105322
5.3 MEDIUM

The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-form actions, allowing unauthenticated users to send arbitrary …

Oct 7, 2026
CVE-2026-104953
6.8 MEDIUM

The MPG WordPress plugin before 4.2.3 does not properly validate the structure of imported project data before using it in a database query, allowing users …

Oct 7, 2026
CVE-2026-104667
6.8 MEDIUM

The Animated Number Counters WordPress plugin before 3.1 does not sanitise or escape a value stored by an Editor-level user before concatenating it into a …

Oct 7, 2026
CVE-2026-104653
6.8 MEDIUM

The Envira Gallery WordPress plugin before 1.16.1 does not sanitise or escape user-supplied gallery display configuration values before storing them and outputting them in an …

Oct 7, 2026
CVE-2026-104652
6.8 MEDIUM

The Envira Gallery WordPress plugin before 1.16.1 does not sanitise and escape a gallery item identifier before outputting it in an image tag attribute, allowing …

Oct 7, 2026
CVE-2026-104651
4.3 MEDIUM

The Yaad Sarig Payment Gateway For WC WordPress plugin before 2.2.13 does not verify authorization or that the requesting user owns the target order in …

Oct 7, 2026
CVE-2026-104050
4.3 MEDIUM

The Academy LMS WordPress plugin before 4.0.0 does not verify that a quiz question belongs to the course the requesting user is authorized to access …

Oct 7, 2026
CVE-2026-104049
4.3 MEDIUM

The Academy LMS WordPress plugin before 4.0.0 does not verify course enrollment or object ownership when returning a lesson's content through one of its REST …

Oct 7, 2026
CVE-2026-103681
4.3 MEDIUM

The Frontend Dashboard WordPress plugin before 3.0.0 does not perform a capability check in one of its AJAX actions, allowing authenticated users with low privileges, …

Oct 7, 2026
CVE-2026-103378
6.5 MEDIUM

The Geliver Akıllı Kargo Pazaryeri WordPress plugin before 3.1.1 does not prevent unauthenticated access to a log file it stores within its own web-accessible directory, …

Oct 7, 2026
CVE-2026-103323
5.9 MEDIUM

The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated …

Oct 7, 2026
CVE-2026-103870
5.0 MEDIUM

A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user …

Oct 7, 2026
CVE-2026-103869
6.5 MEDIUM

A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token …

Oct 7, 2026
CVE-2026-103868
6.5 MEDIUM

A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads …

Oct 7, 2026
CVE-2026-106061
5.5 MEDIUM

A flaw was found in GIMP’s X cursor (XMC) thumbnail loader. When GIMP generates a thumbnail for a crafted XMC file, it allocates a pixel …

Oct 7, 2026
CVE-2026-97671
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.

Oct 7, 2026
CVE-2026-93679
4.3 MEDIUM

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP …

Oct 7, 2026
CVE-2026-93448
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a …

Oct 7, 2026
CVE-2026-101329
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper access control.

Oct 7, 2026
CVE-2026-80048
5.5 MEDIUM

A flaw was found in `sssd-kcm`. A local user or process able to connect to the `sssd-kcm` UNIX socket can exploit this vulnerability. By sending …

Oct 7, 2026
CVE-2026-97626
4.3 MEDIUM

Requesting a user or organization profile page (`GET /{username}`) with an `Accept: application/rss+xml` or `Accept: application/atom+xml` header returned the owner's activity feed without the visibility …

Oct 6, 2026
CVE-2026-97208
4.9 MEDIUM

The Gitea API endpoint for creating push mirrors (`POST /api/v1/repos/{owner}/{repo}/push_mirrors`) checked only whether mirroring was enabled and not the `[mirror] DISABLE_NEW_PUSH` setting that the web …

Oct 6, 2026
CVE-2026-96594
6.1 MEDIUM

The Gitea API endpoint `GET /api/v1/repos/{owner}/{repo}/media/{filepath}` wrote files of up to 1 KiB that are stored directly in Git, not in LFS, to the response …

Oct 6, 2026
CVE-2026-89182
5.4 MEDIUM

With `[repository] FORCE_PRIVATE = true`, Gitea creates new repositories as private, but the post-receive hook still applied the `repo.private=false` push option to an empty repository …

Oct 6, 2026
CVE-2026-65122
5.5 MEDIUM

NVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial …

Oct 6, 2026
CVE-2026-106508
5.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. …

Oct 6, 2026
CVE-2026-106507
5.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. …

Oct 6, 2026
CVE-2026-106506
5.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list …

Oct 6, 2026
CVE-2026-106504
6.5 MEDIUM

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. …

Oct 6, 2026
CVE-2026-106502
5.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under …

Oct 6, 2026
CVE-2026-106499
4.9 MEDIUM

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that …

Oct 6, 2026
CVE-2026-106497
4.3 MEDIUM

Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments …

Oct 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.