CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-97869
4.1 MEDIUM

A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-agentic. This …

Sep 25, 2026
CVE-2026-97469
4.3 MEDIUM

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline …

Sep 25, 2026
CVE-2026-85293
4.8 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and …

Sep 25, 2026
CVE-2026-85292
4.8 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the …

Sep 25, 2026
CVE-2026-85291
6.5 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL …

Sep 25, 2026
CVE-2026-85290
5.3 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from …

Sep 25, 2026
CVE-2026-85289
6.5 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), …

Sep 25, 2026
CVE-2026-85274
6.5 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without …

Sep 25, 2026
CVE-2026-54790
6.0 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it …

Sep 25, 2026
CVE-2026-39372
4.9 MEDIUM

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping …

Sep 25, 2026
CVE-2026-100230
5.3 MEDIUM

Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows …

Sep 25, 2026
CVE-2026-97866
5.6 MEDIUM

A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Automatic …

Sep 25, 2026
CVE-2026-93030
6.5 MEDIUM

FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.

Sep 25, 2026
CVE-2026-88389
6.2 MEDIUM

Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a …

Sep 25, 2026
CVE-2026-97864
5.3 MEDIUM

A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component …

Sep 25, 2026
CVE-2026-97222
5.5 MEDIUM

A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can …

Sep 25, 2026
CVE-2026-88420
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute …

Sep 25, 2026
CVE-2026-78902
6.1 MEDIUM

Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package

Sep 25, 2026
CVE-2026-51772
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an …

Sep 25, 2026
CVE-2026-92573
6.5 MEDIUM

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON …

Sep 25, 2026
CVE-2026-88848
4.2 MEDIUM

The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is covered by their …

Sep 25, 2026
CVE-2026-86837
5.3 MEDIUM

The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored details, allowing unauthenticated attackers who know a customer's …

Sep 25, 2026
CVE-2026-80514
5.3 MEDIUM

The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address headers before using them to key its …

Sep 25, 2026
CVE-2026-96448
6.6 MEDIUM

A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management solution. The issue occurs when the …

Sep 25, 2026
CVE-2026-93747
6.4 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in versions up to, and including, 3.1.6. This …

Sep 25, 2026
CVE-2026-93656
6.4 MEDIUM

The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Sep 25, 2026
CVE-2026-88996
6.1 MEDIUM

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected …

Sep 25, 2026
CVE-2026-17602
4.9 MEDIUM

The SSL Zen — SSL Certificate Installer & HTTPS Redirects plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, …

Sep 25, 2026
CVE-2026-17577
6.1 MEDIUM

The SSL Zen plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'uri' (and 'host') parameters in versions up to, and including, 4.7.42. …

Sep 25, 2026
CVE-2026-13179
6.4 MEDIUM

The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapes_values Parameter in all versions up …

Sep 25, 2026
CVE-2026-12037
5.5 MEDIUM

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.0.5 via the …

Sep 25, 2026
CVE-2026-97846
6.8 MEDIUM

Keycloak provides a feature called mTLS holder-of-key binding which ensures that a token can only be used by the client that originally requested it by …

Sep 25, 2026
CVE-2026-96766
6.4 MEDIUM

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_hours' parameter in …

Sep 25, 2026
CVE-2026-94376
6.4 MEDIUM

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via …

Sep 25, 2026
CVE-2026-93899
6.5 MEDIUM

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to generic SQL Injection via 'group_id' …

Sep 25, 2026
CVE-2026-93897
6.4 MEDIUM

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text-type Custom Field (e.g., …

Sep 25, 2026
CVE-2026-92829
4.3 MEDIUM

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.1.0. This …

Sep 25, 2026
CVE-2026-92799
5.3 MEDIUM

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Authorization Bypass via PHP Type Juggling in all versions up …

Sep 25, 2026
CVE-2026-92746
6.4 MEDIUM

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute …

Sep 25, 2026
CVE-2026-92212
6.1 MEDIUM

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field …

Sep 25, 2026
CVE-2026-78397
4.0 MEDIUM

The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling back to an unprotected fetch when its …

Sep 25, 2026
CVE-2026-78394
4.1 MEDIUM

The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a generated image to disk, allowing users with the …

Sep 25, 2026
CVE-2026-78393
6.1 MEDIUM

The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the addresses of links it generates on its …

Sep 25, 2026
CVE-2026-19775
4.3 MEDIUM

The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Sep 25, 2026
CVE-2026-97736
5.4 MEDIUM

tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.

Sep 25, 2026
CVE-2026-97732
5.1 MEDIUM

IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., …

Sep 25, 2026
CVE-2025-14814
6.4 MEDIUM

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and …

Sep 25, 2026
CVE-2026-97724
4.3 MEDIUM

A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of …

Sep 25, 2026
CVE-2026-97650
4.3 MEDIUM

A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function echo of the file admin/fun/addLog.php. The manipulation …

Sep 25, 2026
CVE-2026-97723
5.4 MEDIUM

madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized …

Sep 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.