CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-97311
4.3 MEDIUM

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with …

Sep 24, 2026
CVE-2026-4806
6.5 MEDIUM

The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check …

Sep 24, 2026
CVE-2026-3253
4.3 MEDIUM

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() …

Sep 24, 2026
CVE-2026-19532
5.3 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: …

Sep 24, 2026
CVE-2026-16302
4.3 MEDIUM

The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the …

Sep 24, 2026
CVE-2026-97179
4.3 MEDIUM

A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of the component Cipher …

Sep 24, 2026
CVE-2026-92905
5.3 MEDIUM

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed …

Sep 24, 2026
CVE-2026-18335
5.4 MEDIUM

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, …

Sep 24, 2026
CVE-2026-15731
6.4 MEDIUM

The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up …

Sep 24, 2026
CVE-2026-78313
6.5 MEDIUM

Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Sep 24, 2026
CVE-2026-78310
4.3 MEDIUM

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Sep 24, 2026
CVE-2026-97181
5.3 MEDIUM

GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.

Sep 24, 2026
CVE-2026-81645
5.9 MEDIUM

Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.

Sep 24, 2026
CVE-2026-97177
6.6 MEDIUM

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to …

Sep 24, 2026
CVE-2026-97176
4.2 MEDIUM

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client …

Sep 24, 2026
CVE-2026-93662
4.3 MEDIUM

The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own …

Sep 24, 2026
CVE-2026-89005
6.8 MEDIUM

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is …

Sep 24, 2026
CVE-2026-89002
6.8 MEDIUM

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which …

Sep 24, 2026
CVE-2026-88847
4.3 MEDIUM

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against …

Sep 24, 2026
CVE-2026-88846
5.3 MEDIUM

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through …

Sep 24, 2026
CVE-2026-88845
4.3 MEDIUM

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated …

Sep 24, 2026
CVE-2026-82850
4.3 MEDIUM

The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve …

Sep 24, 2026
CVE-2026-82849
4.3 MEDIUM

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated …

Sep 24, 2026
CVE-2026-82195
6.5 MEDIUM

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing …

Sep 24, 2026
CVE-2026-80338
6.8 MEDIUM

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low …

Sep 24, 2026
CVE-2026-74991
6.8 MEDIUM

The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting …

Sep 24, 2026
CVE-2026-97155
6.5 MEDIUM

Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins …

Sep 24, 2026
CVE-2026-96892
4.3 MEDIUM

A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of …

Sep 24, 2026
CVE-2026-96884
6.3 MEDIUM

A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the file MainWindow.UI.cs of the …

Sep 24, 2026
CVE-2026-96882
5.3 MEDIUM

A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component …

Sep 24, 2026
CVE-2026-96881
5.3 MEDIUM

A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Executing …

Sep 24, 2026
CVE-2026-97056
6.8 MEDIUM

SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), …

Sep 24, 2026
CVE-2026-96880
5.3 MEDIUM

A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing …

Sep 24, 2026
CVE-2026-96777
6.3 MEDIUM

A vulnerability was determined in Forma LMS up to 4.1.43. This impacts the function UserselectorAdmController::getDataTask of the file /appCore/ajax.adm_server.php?r=adm/userselector/getData of the component Multi-User-Selector AJAX Endpoint. …

Sep 24, 2026
CVE-2026-96774
5.3 MEDIUM

A vulnerability was found in SPON Communications IP Network Audio Device XC-9603 1.2.3_20181106 Build 107. This affects the function loadCfg of the file /ini/sys_cfg.txt of …

Sep 24, 2026
CVE-2026-96773
4.3 MEDIUM

A weakness has been identified in Intelliants Subrion CMS up to 4.2.1. This vulnerability affects the function iaUsers::authorize of the file front/login.php of the component …

Sep 24, 2026
CVE-2026-96772
5.3 MEDIUM

A security flaw has been discovered in Intelliants Subrion CMS up to 4.2.1. This affects an unknown part of the file /actions.json?action=assign-owner. The manipulation of …

Sep 24, 2026
CVE-2026-96764
4.3 MEDIUM

A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation …

Sep 24, 2026
CVE-2026-96763
5.4 MEDIUM

A security flaw has been discovered in kvcache-ai mooncake up to 0.3.12/0.3.13.post1/0.3.14-rc1. This issue affects the function ScopedSegmentAccess::MountSegment of the file segment.cpp of the component …

Sep 24, 2026
CVE-2026-96739
4.3 MEDIUM

A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component …

Sep 24, 2026
CVE-2026-92874
5.4 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain …

Sep 24, 2026
CVE-2026-92530
4.3 MEDIUM

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain …

Sep 24, 2026
CVE-2026-92529
4.3 MEDIUM

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain …

Sep 24, 2026
CVE-2026-96680
4.3 MEDIUM

A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of …

Sep 23, 2026
CVE-2026-96678
6.3 MEDIUM

A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/util/NewUserFormValidator.java of the component Avatar …

Sep 23, 2026
CVE-2026-96676
6.3 MEDIUM

A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer …

Sep 23, 2026
CVE-2026-96606
5.3 MEDIUM

A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. This vulnerability affects unknown code of the file Mifi_config.bin of the component Configuration Backup Handler. …

Sep 23, 2026
CVE-2026-6925
5.3 MEDIUM

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Sep 23, 2026
CVE-2026-6718
6.2 MEDIUM

IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of application files.

Sep 23, 2026
CVE-2026-96551
4.3 MEDIUM

A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java. Executing a manipulation can lead to …

Sep 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.