CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23570
4.3 MEDIUM

HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on …

Jul 17, 2026
CVE-2024-23569
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

Jul 17, 2026
CVE-2024-23568
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information …

Jul 17, 2026
CVE-2024-23567
4.3 MEDIUM

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during …

Jul 17, 2026
CVE-2024-23566
6.5 MEDIUM

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force …

Jul 17, 2026
CVE-2024-23565
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor …

Jul 17, 2026
CVE-2026-13082
5.3 MEDIUM

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters …

Jul 17, 2026
CVE-2026-16013
5.3 MEDIUM

A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation …

Jul 17, 2026
CVE-2026-16009
6.3 MEDIUM

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid …

Jul 17, 2026
CVE-2026-15943
5.5 MEDIUM

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an …

Jul 17, 2026
CVE-2026-9602
6.5 MEDIUM

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious …

Jul 17, 2026
CVE-2026-8075
6.5 MEDIUM

Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user …

Jul 17, 2026
CVE-2026-16008
6.3 MEDIUM

A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled …

Jul 17, 2026
CVE-2026-9656
4.3 MEDIUM

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Jul 17, 2026
CVE-2026-13402
5.3 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one …

Jul 17, 2026
CVE-2026-12393
5.4 MEDIUM

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing …

Jul 17, 2026
CVE-2026-11966
5.3 MEDIUM

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions …

Jul 17, 2026
CVE-2026-10525
6.1 MEDIUM

The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin …

Jul 17, 2026
CVE-2026-15094
6.1 MEDIUM

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 …

Jul 17, 2026
CVE-2026-60060
6.3 MEDIUM

Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish …

Jul 17, 2026
CVE-2026-58317
6.3 MEDIUM

Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an …

Jul 17, 2026
CVE-2026-41993
4.4 MEDIUM

Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file …

Jul 17, 2026
CVE-2026-21770
6.5 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with …

Jul 17, 2026
CVE-2026-15759
6.4 MEDIUM

The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 17, 2026
CVE-2026-15457
4.9 MEDIUM

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, …

Jul 17, 2026
CVE-2026-15349
4.3 MEDIUM

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Jul 17, 2026
CVE-2026-15161
6.4 MEDIUM

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due …

Jul 17, 2026
CVE-2026-14503
6.5 MEDIUM

The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This …

Jul 17, 2026
CVE-2026-8616
5.3 MEDIUM

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce …

Jul 17, 2026
CVE-2026-15160
4.3 MEDIUM

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' …

Jul 17, 2026
CVE-2026-15159
4.3 MEDIUM

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via …

Jul 17, 2026
CVE-2026-11324
6.1 MEDIUM

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and …

Jul 17, 2026
CVE-2026-62237
6.5 MEDIUM

Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content …

Jul 17, 2026
CVE-2026-62236
5.4 MEDIUM

grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a new TOTP secret for the …

Jul 17, 2026
CVE-2026-62235
6.3 MEDIUM

Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permission to …

Jul 17, 2026
CVE-2026-62225
5.4 MEDIUM

OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions beyond their intended …

Jul 17, 2026
CVE-2026-62224
5.4 MEDIUM

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust access can perform …

Jul 17, 2026
CVE-2026-62221
5.4 MEDIUM

OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable, a lower-trust caller …

Jul 17, 2026
CVE-2026-62220
5.3 MEDIUM

OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the affected feature …

Jul 17, 2026
CVE-2026-62216
5.0 MEDIUM

OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media …

Jul 17, 2026
CVE-2026-62214
6.5 MEDIUM

OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by failing to …

Jul 17, 2026
CVE-2026-62213
6.5 MEDIUM

OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attackers can …

Jul 17, 2026
CVE-2026-62211
5.0 MEDIUM

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain …

Jul 17, 2026
CVE-2026-62210
6.5 MEDIUM

OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Attackers with …

Jul 17, 2026
CVE-2026-62208
6.5 MEDIUM

OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configured input …

Jul 17, 2026
CVE-2026-44251
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t …

Jul 17, 2026
CVE-2026-40106
4.7 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based …

Jul 17, 2026
CVE-2026-2594
6.4 MEDIUM

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient …

Jul 17, 2026
CVE-2026-33754
6.5 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote …

Jul 17, 2026
CVE-2026-33434
4.3 MEDIUM

Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic …

Jul 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.