CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-84724
6.6 MEDIUM

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running …

Sep 23, 2026
CVE-2026-84721
6.4 MEDIUM

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and …

Sep 23, 2026
CVE-2026-84720
6.5 MEDIUM

A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, …

Sep 23, 2026
CVE-2026-84718
4.3 MEDIUM

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's …

Sep 23, 2026
CVE-2026-84717
5.3 MEDIUM

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after …

Sep 23, 2026
CVE-2026-84716
6.6 MEDIUM

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 …

Sep 23, 2026
CVE-2026-84713
6.5 MEDIUM

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in clear text …

Sep 23, 2026
CVE-2026-84712
5.3 MEDIUM

A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the …

Sep 23, 2026
CVE-2026-96548
5.6 MEDIUM

A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. …

Sep 23, 2026
CVE-2026-96545
4.4 MEDIUM

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to …

Sep 23, 2026
CVE-2026-95602
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH …

Sep 23, 2026
CVE-2026-95600
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.

Sep 23, 2026
CVE-2026-95592
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

Sep 23, 2026
CVE-2026-95586
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

Sep 23, 2026
CVE-2026-95530
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.

Sep 23, 2026
CVE-2026-95527
6.5 MEDIUM

Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.

Sep 23, 2026
CVE-2026-95525
6.5 MEDIUM

Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.

Sep 23, 2026
CVE-2026-95524
5.3 MEDIUM

Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

Sep 23, 2026
CVE-2026-95523
6.5 MEDIUM

Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

Sep 23, 2026
CVE-2026-95514
5.3 MEDIUM

Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.

Sep 23, 2026
CVE-2026-94684
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.

Sep 23, 2026
CVE-2026-94682
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.

Sep 23, 2026
CVE-2026-94680
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

Sep 23, 2026
CVE-2026-94679
5.4 MEDIUM

Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.

Sep 23, 2026
CVE-2026-94671
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

Sep 23, 2026
CVE-2026-94500
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.

Sep 23, 2026
CVE-2026-94498
6.5 MEDIUM

Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.

Sep 23, 2026
CVE-2026-94461
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.

Sep 23, 2026
CVE-2026-94457
4.8 MEDIUM

Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.

Sep 23, 2026
CVE-2026-94391
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.

Sep 23, 2026
CVE-2026-94168
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

Sep 23, 2026
CVE-2026-94118
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.

Sep 23, 2026
CVE-2026-94080
5.3 MEDIUM

Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.

Sep 23, 2026
CVE-2026-94079
5.3 MEDIUM

Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.

Sep 23, 2026
CVE-2026-93772
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.

Sep 23, 2026
CVE-2026-93623
5.3 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.

Sep 23, 2026
CVE-2026-93620
6.5 MEDIUM

Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.

Sep 23, 2026
CVE-2026-93618
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a …

Sep 23, 2026
CVE-2026-93529
6.5 MEDIUM

Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.

Sep 23, 2026
CVE-2026-93513
4.3 MEDIUM

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

Sep 23, 2026
CVE-2026-77421
6.5 MEDIUM

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a …

Sep 23, 2026
CVE-2026-77420
5.5 MEDIUM

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration …

Sep 23, 2026
CVE-2026-71462
4.1 MEDIUM

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenant superuser can confirm …

Sep 23, 2026
CVE-2026-71461
4.3 MEDIUM

HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse …

Sep 23, 2026
CVE-2026-71460
4.3 MEDIUM

/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuser/auditor gate only covers project_base_dir/project_local_paths/custom_virtualenvs, …

Sep 23, 2026
CVE-2026-71459
5.0 MEDIUM

JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_404(Job, pk) without DRF object-level permission check. …

Sep 23, 2026
CVE-2026-71458
5.0 MEDIUM

URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 …

Sep 23, 2026
CVE-2026-55632
4.3 MEDIUM

GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompletion while editing pipeline, template, environment, and user-preference …

Sep 23, 2026
CVE-2026-88840
5.3 MEDIUM

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

Sep 23, 2026
CVE-2026-88839
6.7 MEDIUM

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

Sep 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.