CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-86604
4.8 MEDIUM

The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expanding them which, in a non-default configuration, allows …

Sep 23, 2026
CVE-2026-86601
6.5 MEDIUM

The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it while building a page's structured metadata, allowing …

Sep 23, 2026
CVE-2026-96443
6.5 MEDIUM

Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution on the FE.

Sep 23, 2026
CVE-2026-94251
6.5 MEDIUM

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. …

Sep 23, 2026
CVE-2026-92001
6.1 MEDIUM

Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users …

Sep 23, 2026
CVE-2026-91999
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are …

Sep 23, 2026
CVE-2026-91928
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are …

Sep 23, 2026
CVE-2026-91852
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are …

Sep 23, 2026
CVE-2026-73192
6.1 MEDIUM

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior …

Sep 23, 2026
CVE-2026-95625
5.9 MEDIUM

The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains …

Sep 23, 2026
CVE-2026-91817
6.1 MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause …

Sep 23, 2026
CVE-2026-91814
5.3 MEDIUM

A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing …

Sep 23, 2026
CVE-2026-91810
6.1 MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during …

Sep 23, 2026
CVE-2026-91808
6.1 MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding …

Sep 23, 2026
CVE-2026-91807
6.1 MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed image soft-mask data. Insufficient validation of the soft-mask data attribute during image …

Sep 23, 2026
CVE-2026-91796
6.1 MEDIUM

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without …

Sep 23, 2026
CVE-2026-91788
4.7 MEDIUM

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious …

Sep 23, 2026
CVE-2026-6831
6.5 MEDIUM

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 2.0.9. This is due …

Sep 23, 2026
CVE-2026-5924
6.4 MEDIUM

The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps block's 'customStyle' attribute in all versions up …

Sep 23, 2026
CVE-2026-93511
5.3 MEDIUM

The Premium Packages WordPress plugin before 7.2.1 does not verify PayPal's webhook signature before processing payment and subscription notifications, allowing unauthenticated attackers to forge payment …

Sep 23, 2026
CVE-2026-93510
4.3 MEDIUM

The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel …

Sep 23, 2026
CVE-2026-91073
6.8 MEDIUM

The Subscribe Forms WordPress plugin before 1.6.3 does not sanitise and escape one of its form settings before outputting it in a page, allowing authenticated …

Sep 23, 2026
CVE-2026-91025
4.3 MEDIUM

The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets …

Sep 23, 2026
CVE-2026-91024
6.8 MEDIUM

The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a …

Sep 23, 2026
CVE-2026-90985
5.3 MEDIUM

The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 does not apply WordPress's post-password protection when returning product content through its comparison handler, allowing …

Sep 23, 2026
CVE-2026-89331
5.3 MEDIUM

The FluentBoards WordPress plugin before 2.1.0 does not properly restrict the member data returned by its public, token-shared board feature, allowing unauthenticated users to disclose …

Sep 23, 2026
CVE-2026-88997
6.8 MEDIUM

The JSM Show Post Metadata WordPress plugin before 4.9.1 does not properly escape a post meta key before outputting it into an inline event-handler attribute …

Sep 23, 2026
CVE-2026-88929
5.3 MEDIUM

The Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin before 7.5.2 does not check whether a product is published before returning its details to …

Sep 23, 2026
CVE-2026-87981
4.7 MEDIUM

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not perform a capability check on several admin AJAX actions that manage its payment-gateway configuration, allowing …

Sep 23, 2026
CVE-2026-87979
5.3 MEDIUM

The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on the card-token branch of its payment webhook, allowing unauthenticated attackers …

Sep 23, 2026
CVE-2026-86842
6.8 MEDIUM

The Real3D Flipbook WordPress plugin before 5.4 does not perform capability checks on several of its authenticated flipbook management actions, allowing users with Author-level access …

Sep 23, 2026
CVE-2026-86785
5.3 MEDIUM

The Social Commerce for WooCommerce WordPress plugin through 2.5.4 does not have authorisation checks on some of its REST API endpoints, allowing unauthenticated users to …

Sep 23, 2026
CVE-2026-86783
5.3 MEDIUM

The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the …

Sep 23, 2026
CVE-2026-86603
4.3 MEDIUM

The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its AJAX actions, allowing any authenticated user, such …

Sep 23, 2026
CVE-2026-86602
4.3 MEDIUM

The WP Recipe Maker WordPress plugin before 10.8.2 does not perform any capability check in one of its AJAX actions, allowing any authenticated user, such …

Sep 23, 2026
CVE-2026-85006
6.8 MEDIUM

The HappyAddons for Elementor WordPress plugin before 3.50.0 does not escape an icon value on one of its button widgets before outputting it inside an …

Sep 23, 2026
CVE-2026-84741
5.3 MEDIUM

The Events Calendar WordPress plugin before 6.17.5 does not check the post status of linked records before embedding their stored details into a public REST …

Sep 23, 2026
CVE-2026-84168
5.3 MEDIUM

The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page …

Sep 23, 2026
CVE-2026-84150
5.4 MEDIUM

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not verify that the target user of a REST route matches …

Sep 23, 2026
CVE-2026-84098
6.5 MEDIUM

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not properly verify a listing's ownership before deleting it, allowing authenticated …

Sep 23, 2026
CVE-2026-84046
5.0 MEDIUM

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not validate a user-supplied URL before fetching it server-side, allowing users …

Sep 23, 2026
CVE-2026-84027
4.3 MEDIUM

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not check user capabilities when creating orders through its REST API, …

Sep 23, 2026
CVE-2026-84026
5.3 MEDIUM

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not restrict access to a REST endpoint that returns user records, …

Sep 23, 2026
CVE-2026-83555
5.3 MEDIUM

The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users …

Sep 23, 2026
CVE-2026-81339
4.3 MEDIUM

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform a per-object ownership check when returning a quiz attempt result, allowing any authenticated …

Sep 23, 2026
CVE-2026-81338
4.6 MEDIUM

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not properly sanitise and restrict HTML in user-submitted content before storing it and rendering it …

Sep 23, 2026
CVE-2026-80342
6.5 MEDIUM

The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.27 does not verify that a PayPal order supplied in a payment request belongs to the …

Sep 23, 2026
CVE-2026-77766
4.3 MEDIUM

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.5 does not scope one of its REST collection endpoints to the requesting …

Sep 23, 2026
CVE-2026-77765
5.3 MEDIUM

The Better Payment WordPress plugin before 2.3.4 does not validate the submitted payment amount server-side against the merchant's configured fixed price before building the gateway …

Sep 23, 2026
CVE-2026-18365
4.3 MEDIUM

The zportals WordPress plugin before 6.4.2 does not perform any capability or nonce check on one of its AJAX actions, allowing users with a subscriber-level …

Sep 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.