CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-87909
7.5 HIGH

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to …

Sep 19, 2026
CVE-2026-13354
7.2 HIGH

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, …

Sep 19, 2026
CVE-2026-93923
8.8 HIGH

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks …

Sep 19, 2026
CVE-2026-93922
8.8 HIGH

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. …

Sep 19, 2026
CVE-2026-88097
8.1 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

Sep 18, 2026
CVE-2026-71418
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously …

Sep 18, 2026
CVE-2026-68928
8.6 HIGH

Acode is a powerful text and code editor for Android. From 1.11.6 until 1.12.7, com.foxdebug.acode.rk.exec.terminal.TerminalService is declared as an exported service in src/plugins/terminal/plugin.xml without a …

Sep 18, 2026
CVE-2026-63452
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work …

Sep 18, 2026
CVE-2026-63447
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can …

Sep 18, 2026
CVE-2026-63446
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted …

Sep 18, 2026
CVE-2026-57228
8.2 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in …

Sep 18, 2026
CVE-2026-57227
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in …

Sep 18, 2026
CVE-2026-57223
7.0 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and …

Sep 18, 2026
CVE-2026-93872
7.5 HIGH

Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate …

Sep 18, 2026
CVE-2026-93868
8.1 HIGH

Cotonti through 1.0.0 derives password recovery validation tokens from md5(microtime()) in users.passrecover.php, creating a predictable token space of approximately one million values per second. Unauthenticated …

Sep 18, 2026
CVE-2026-93031
8.8 HIGH

The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable to Arbitrary File Upload in all versions from 2.0 up to, …

Sep 18, 2026
CVE-2026-92708
7.5 HIGH

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. In versions 5.1.0 through 5.9.2, stringify and …

Sep 18, 2026
CVE-2026-84241
8.1 HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper authorization.

Sep 18, 2026
CVE-2026-84239
7.6 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an …

Sep 18, 2026
CVE-2026-84108
8.1 HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Sep 18, 2026
CVE-2026-84106
8.9 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Sep 18, 2026
CVE-2026-84105
7.7 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper neutralization of special elements used in an …

Sep 18, 2026
CVE-2026-84089
7.8 HIGH

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

Sep 18, 2026
CVE-2026-84086
7.2 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted …

Sep 18, 2026
CVE-2026-84085
8.1 HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an …

Sep 18, 2026
CVE-2026-84084
8.8 HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

Sep 18, 2026
CVE-2026-84083
7.8 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged …

Sep 18, 2026
CVE-2026-84081
8.1 HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

Sep 18, 2026
CVE-2026-84077
8.1 HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

Sep 18, 2026
CVE-2026-84076
7.6 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

Sep 18, 2026
CVE-2026-84074
8.9 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Sep 18, 2026
CVE-2026-84071
7.2 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a …

Sep 18, 2026
CVE-2026-84070
8.9 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Sep 18, 2026
CVE-2026-84036
7.4 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

Sep 18, 2026
CVE-2026-84034
8.8 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master …

Sep 18, 2026
CVE-2026-82896
7.6 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

Sep 18, 2026
CVE-2026-82893
7.8 HIGH

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

Sep 18, 2026
CVE-2026-82892
8.1 HIGH

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS …

Sep 18, 2026
CVE-2026-82887
8.8 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an …

Sep 18, 2026
CVE-2026-82885
8.8 HIGH

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

Sep 18, 2026
CVE-2026-81937
7.2 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can …

Sep 18, 2026
CVE-2026-81933
8.8 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL …

Sep 18, 2026
CVE-2026-81669
7.2 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can …

Sep 18, 2026
CVE-2026-81656
8.8 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject …

Sep 18, 2026
CVE-2026-81626
8.6 HIGH

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements …

Sep 18, 2026
CVE-2026-75895
7.5 HIGH

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to …

Sep 18, 2026
CVE-2026-61821
8.5 HIGH

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for …

Sep 18, 2026
CVE-2026-61820
8.5 HIGH

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with …

Sep 18, 2026
CVE-2026-61819
8.5 HIGH

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception …

Sep 18, 2026
CVE-2026-61818
8.5 HIGH

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it …

Sep 18, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.