CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-95501
4.3 MEDIUM

A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.php of the component Template …

Sep 22, 2026
CVE-2026-94570
5.9 MEDIUM

SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker …

Sep 22, 2026
CVE-2026-93344
6.5 MEDIUM

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher …

Sep 22, 2026
CVE-2026-79315
4.7 MEDIUM

A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for …

Sep 22, 2026
CVE-2026-65129
6.7 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to …

Sep 22, 2026
CVE-2026-65127
4.1 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful …

Sep 22, 2026
CVE-2026-65126
5.0 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability …

Sep 22, 2026
CVE-2026-65125
6.6 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of …

Sep 22, 2026
CVE-2026-65124
5.9 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to …

Sep 22, 2026
CVE-2026-65117
5.0 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might …

Sep 22, 2026
CVE-2026-65115
6.5 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to …

Sep 22, 2026
CVE-2026-65112
6.5 MEDIUM

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to …

Sep 22, 2026
CVE-2026-95666
4.3 MEDIUM

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted …

Sep 22, 2026
CVE-2026-95396
4.3 MEDIUM

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the component Public Search Handlers. …

Sep 22, 2026
CVE-2026-93343
6.5 MEDIUM

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher …

Sep 22, 2026
CVE-2026-93342
5.4 MEDIUM

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher …

Sep 22, 2026
CVE-2026-93341
4.3 MEDIUM

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher …

Sep 22, 2026
CVE-2026-95273
4.3 MEDIUM

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a …

Sep 22, 2026
CVE-2026-95623
5.6 MEDIUM

The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with …

Sep 22, 2026
CVE-2026-25262
6.9 MEDIUM

Memory corruption while processing a crafted ELF file in the Primary Bootloader.

Sep 22, 2026
CVE-2026-15095
4.9 MEDIUM

The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in …

Sep 22, 2026
CVE-2026-9004
4.3 MEDIUM

The WP-CRM System – Manage Clients and Projects plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.6 …

Sep 22, 2026
CVE-2026-95503
6.8 MEDIUM

A flaw was found in the Kerberos federation provider of Keycloak, an open-source identity and access management solution. When Kerberos password authentication is used without …

Sep 22, 2026
CVE-2026-91092
4.3 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin …

Sep 22, 2026
CVE-2026-7622
4.3 MEDIUM

The ThumbPress plugin for WordPress is vulnerable to unauthorized access in versions up to and including 6.2.1. This is due to missing capability checks and …

Sep 22, 2026
CVE-2026-74765
6.5 MEDIUM

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode …

Sep 22, 2026
CVE-2026-4123
4.3 MEDIUM

The RW Elephant Rental Inventory plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 2.3.13. This is due to …

Sep 22, 2026
CVE-2026-1645
4.4 MEDIUM

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_currency' parameter and the 'locale_url' setting in all versions up to, and …

Sep 22, 2026
CVE-2026-18439
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, …

Sep 22, 2026
CVE-2026-18345
4.3 MEDIUM

The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in …

Sep 22, 2026
CVE-2026-16778
6.4 MEDIUM

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up …

Sep 22, 2026
CVE-2026-12995
4.3 MEDIUM

The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value …

Sep 22, 2026
CVE-2025-1280
6.5 MEDIUM

The BM Content Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to 3.17.1 (exclusive) via the ux_cb_page_customize_save_layout_ajax() function. This makes …

Sep 22, 2026
CVE-2025-14487
5.3 MEDIUM

The Handily plugin for WordPress is vulnerable to unauthorized payment settings modification due to missing authorization checks in all versions up to, and including, 1.0.3. …

Sep 22, 2026
CVE-2025-14486
5.3 MEDIUM

The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. …

Sep 22, 2026
CVE-2025-14484
5.3 MEDIUM

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, …

Sep 22, 2026
CVE-2026-93655
6.1 MEDIUM

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpbc_auto_fill' parameter in all versions up to, and including, 11.8.3 due …

Sep 22, 2026
CVE-2026-88788
6.8 MEDIUM

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does …

Sep 22, 2026
CVE-2026-85653
6.4 MEDIUM

The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'other_attributes' Block Parameter in all versions up to, and including, 4.4.1 …

Sep 22, 2026
CVE-2026-94492
6.3 MEDIUM

A security vulnerability has been detected in Yonyou U8cloud 5.x. This vulnerability affects unknown code of the file /u8cloud/openapi/so.saleorder.sendaudit of the component OpenAPI. The manipulation …

Sep 22, 2026
CVE-2026-93711
6.5 MEDIUM

Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from response header names in headers_to_array. The routine removes CR and LF from …

Sep 22, 2026
CVE-2026-93709
5.3 MEDIUM

Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage …

Sep 22, 2026
CVE-2026-76974
5.3 MEDIUM

SAP Fiori Launchpad does not sufficiently validate certain user-controlled input. An unauthenticated attacker could craft a malicious link that, when clicked by an authenticated user, …

Sep 22, 2026
CVE-2026-94490
4.7 MEDIUM

A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command …

Sep 22, 2026
CVE-2026-94489
4.3 MEDIUM

A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. …

Sep 22, 2026
CVE-2026-94625
5.3 MEDIUM

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send …

Sep 21, 2026
CVE-2026-94536
4.3 MEDIUM

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can …

Sep 21, 2026
CVE-2026-94533
6.5 MEDIUM

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files …

Sep 21, 2026
CVE-2026-94532
6.5 MEDIUM

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can …

Sep 21, 2026
CVE-2026-93340
6.8 MEDIUM

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account …

Sep 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.