CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-94110
7.3 HIGH

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content …

Sep 21, 2026
CVE-2026-94044
7.3 HIGH

A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument …

Sep 20, 2026
CVE-2026-94039
7.3 HIGH

A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. …

Sep 20, 2026
CVE-2026-94038
7.3 HIGH

A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation …

Sep 20, 2026
CVE-2026-94036
8.8 HIGH

A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus …

Sep 20, 2026
CVE-2026-94015
7.3 HIGH

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID …

Sep 20, 2026
CVE-2026-94109
8.0 HIGH

openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by …

Sep 20, 2026
CVE-2026-94107
8.1 HIGH

NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know …

Sep 20, 2026
CVE-2026-94106
8.8 HIGH

getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames …

Sep 20, 2026
CVE-2026-94104
8.8 HIGH

NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails to validate file extensions for new filenames or …

Sep 20, 2026
CVE-2026-94004
7.3 HIGH

A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_js.php. The manipulation of the argument …

Sep 20, 2026
CVE-2026-93997
7.3 HIGH

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation …

Sep 20, 2026
CVE-2026-93980
7.3 HIGH

A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login …

Sep 20, 2026
CVE-2026-93979
7.3 HIGH

A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of …

Sep 20, 2026
CVE-2026-93978
7.3 HIGH

A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of …

Sep 20, 2026
CVE-2026-93974
7.3 HIGH

A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of …

Sep 20, 2026
CVE-2026-93973
7.3 HIGH

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation …

Sep 20, 2026
CVE-2026-93972
7.3 HIGH

A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such …

Sep 20, 2026
CVE-2026-93970
7.3 HIGH

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. …

Sep 20, 2026
CVE-2026-93969
7.3 HIGH

A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The …

Sep 20, 2026
CVE-2026-92541
7.2 HIGH

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with …

Sep 20, 2026
CVE-2026-92540
7.2 HIGH

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, …

Sep 20, 2026
CVE-2026-87839
7.5 HIGH

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX …

Sep 20, 2026
CVE-2026-87067
8.5 HIGH

The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, …

Sep 20, 2026
CVE-2026-85017
7.5 HIGH

The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through …

Sep 20, 2026
CVE-2026-82842
8.1 HIGH

The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress …

Sep 20, 2026
CVE-2026-81650
7.2 HIGH

The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not correctly validate the extensions of files extracted from an uploaded archive, due to …

Sep 20, 2026
CVE-2026-93962
8.3 HIGH

A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP …

Sep 20, 2026
CVE-2026-86553
8.8 HIGH

SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call …

Sep 20, 2026
CVE-2026-93959
7.3 HIGH

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the …

Sep 20, 2026
CVE-2026-94056
7.5 HIGH

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

Sep 19, 2026
CVE-2026-94054
7.0 HIGH

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

Sep 19, 2026
CVE-2026-93993
8.8 HIGH

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply …

Sep 19, 2026
CVE-2026-93992
8.1 HIGH

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft …

Sep 19, 2026
CVE-2026-93991
7.7 HIGH

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector …

Sep 19, 2026
CVE-2026-93990
7.5 HIGH

Expat through 2.8.4 fails to validate low surrogates following high surrogates in UTF-16 input, allowing malformed UTF-16 sequences to be accepted. Attackers can craft UTF-16 …

Sep 19, 2026
CVE-2026-82560
7.5 HIGH

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. …

Sep 19, 2026
CVE-2026-1255
7.5 HIGH

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX …

Sep 19, 2026
CVE-2026-85658
8.1 HIGH

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode …

Sep 19, 2026
CVE-2026-4327
8.8 HIGH

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing …

Sep 19, 2026
CVE-2026-15664
7.2 HIGH

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value …

Sep 19, 2026
CVE-2026-92404
7.5 HIGH

The MgoSync WordPress plugin before 2.1.7 does not have authorization controls on one of its REST API endpoints, allowing unauthenticated users to retrieve the stored …

Sep 19, 2026
CVE-2026-88926
8.6 HIGH

The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of its parameters before using them in SQL statements, …

Sep 19, 2026
CVE-2026-88824
8.8 HIGH

The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including …

Sep 19, 2026
CVE-2026-86814
8.1 HIGH

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to …

Sep 19, 2026
CVE-2026-85680
8.8 HIGH

The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names before outputting it in the page title, …

Sep 19, 2026
CVE-2026-85574
8.0 HIGH

The Unbounce Landing Pages WordPress plugin before 1.1.5 does not perform any authorisation check when updating the configuration its front-end proxy relies on, allowing any …

Sep 19, 2026
CVE-2026-76790
7.1 HIGH

The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back …

Sep 19, 2026
CVE-2026-76554
7.2 HIGH

The WP Import Export Lite WordPress plugin before 3.9.35 does not verify that the user running an import is permitted to create or modify user …

Sep 19, 2026
CVE-2026-92807
8.8 HIGH

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via …

Sep 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.