CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-96826
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection. This …

Sep 23, 2026
CVE-2026-94183
7.4 HIGH

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in …

Sep 23, 2026
CVE-2026-86065
7.5 HIGH

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with …

Sep 23, 2026
CVE-2026-86064
8.6 HIGH

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by …

Sep 23, 2026
CVE-2026-85475
7.2 HIGH

A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH …

Sep 23, 2026
CVE-2026-84714
7.1 HIGH

A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at …

Sep 23, 2026
CVE-2026-84706
7.6 HIGH

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check …

Sep 23, 2026
CVE-2026-84691
8.7 HIGH

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is …

Sep 23, 2026
CVE-2026-84683
8.7 HIGH

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update …

Sep 23, 2026
CVE-2026-96541
7.5 HIGH

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely …

Sep 23, 2026
CVE-2026-95604
7.5 HIGH

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

Sep 23, 2026
CVE-2026-95603
7.2 HIGH

Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.

Sep 23, 2026
CVE-2026-95593
7.6 HIGH

Editor SQL Injection in Ultimeter <= 3.0.8 versions.

Sep 23, 2026
CVE-2026-95590
7.1 HIGH

Subscriber SQL Injection in Tainacan <= 1.2.0 versions.

Sep 23, 2026
CVE-2026-95529
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.

Sep 23, 2026
CVE-2026-95528
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

Sep 23, 2026
CVE-2026-95522
7.6 HIGH

Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.

Sep 23, 2026
CVE-2026-95515
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.

Sep 23, 2026
CVE-2026-95513
7.5 HIGH

Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.

Sep 23, 2026
CVE-2026-94487
8.1 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.

Sep 23, 2026
CVE-2026-94181
7.4 HIGH

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that …

Sep 23, 2026
CVE-2026-94179
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.

Sep 23, 2026
CVE-2026-94176
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.

Sep 23, 2026
CVE-2026-94174
7.6 HIGH

Administrator SQL Injection in Email Log <= 2.63 versions.

Sep 23, 2026
CVE-2026-94124
8.5 HIGH

Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.

Sep 23, 2026
CVE-2026-93774
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.

Sep 23, 2026
CVE-2026-93773
8.5 HIGH

Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.

Sep 23, 2026
CVE-2026-93622
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.

Sep 23, 2026
CVE-2026-93527
8.5 HIGH

Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

Sep 23, 2026
CVE-2026-93526
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.

Sep 23, 2026
CVE-2026-84499
7.7 HIGH

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as …

Sep 23, 2026
CVE-2026-84486
8.2 HIGH

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are …

Sep 23, 2026
CVE-2026-82356
7.5 HIGH

Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely …

Sep 23, 2026
CVE-2026-77601
8.8 HIGH

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated …

Sep 23, 2026
CVE-2026-77423
7.5 HIGH

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter …

Sep 23, 2026
CVE-2026-77422
7.5 HIGH

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled …

Sep 23, 2026
CVE-2026-77394
7.6 HIGH

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated …

Sep 23, 2026
CVE-2026-76648
8.5 HIGH

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — …

Sep 23, 2026
CVE-2026-76089
7.7 HIGH

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-supplied notification …

Sep 23, 2026
CVE-2026-76087
8.2 HIGH

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when …

Sep 23, 2026
CVE-2026-76086
8.5 HIGH

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the …

Sep 23, 2026
CVE-2026-75131
7.8 HIGH

NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code …

Sep 23, 2026
CVE-2026-61814
7.5 HIGH

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many …

Sep 23, 2026
CVE-2026-61695
7.5 HIGH

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length …

Sep 23, 2026
CVE-2026-59990
7.5 HIGH

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nesting without a depth limit, …

Sep 23, 2026
CVE-2026-86938
7.3 HIGH

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing …

Sep 23, 2026
CVE-2026-86926
7.8 HIGH

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, …

Sep 23, 2026
CVE-2026-96808
7.4 HIGH

In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. …

Sep 23, 2026
CVE-2026-96804
8.8 HIGH

MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via …

Sep 23, 2026
CVE-2026-96775
8.8 HIGH

MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute …

Sep 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.