CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-92967
6.1 MEDIUM

The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword' parameter in versions up to, and including, 1.20.2. This is due …

Sep 19, 2026
CVE-2026-89334
6.5 MEDIUM

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to authorization bypass in all versions …

Sep 19, 2026
CVE-2026-89333
6.5 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Sep 19, 2026
CVE-2026-89093
5.3 MEDIUM

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Information Exposure by Spoofing in …

Sep 19, 2026
CVE-2026-89081
6.1 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search' parameter in all versions …

Sep 19, 2026
CVE-2026-88944
4.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.8. …

Sep 19, 2026
CVE-2026-15760
6.5 MEDIUM

The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in versions up to, and including, 5.8.1 via the dnxte_get_database_tables and dnxte_get_database_data AJAX …

Sep 19, 2026
CVE-2026-15660
4.3 MEDIUM

The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.4.7. This is due to a missing capability …

Sep 19, 2026
CVE-2026-12042
4.4 MEDIUM

The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due …

Sep 19, 2026
CVE-2026-77820
6.4 MEDIUM

The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty' Shortcode Attribute in all versions up to, and including, 2.9.9.0 due to …

Sep 19, 2026
CVE-2026-93921
4.3 MEDIUM

SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon endpoint, allowing read-only token holders to access document metadata. Attackers can call …

Sep 19, 2026
CVE-2026-93574
6.5 MEDIUM

A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes …

Sep 18, 2026
CVE-2026-93562
6.5 MEDIUM

A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending …

Sep 18, 2026
CVE-2026-85272
4.3 MEDIUM

Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawood.1, openedx/core/lib/extract_archive.py uses _is_bad_path to validate …

Sep 18, 2026
CVE-2026-85271
6.1 MEDIUM

Open edX Platform enables the authoring and delivery of online learning at any scale. From Redwood until Ulmo and Verawood.1, the add_additional_attributes_to_notifications function in openedx/core/djangoapps/notifications/email/utils.py …

Sep 18, 2026
CVE-2026-71855
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, src/flow-hash.c can treat an IPv4 …

Sep 18, 2026
CVE-2026-63448
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the SMB parser can retain …

Sep 18, 2026
CVE-2026-61670
6.5 MEDIUM

microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox …

Sep 18, 2026
CVE-2026-57229
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the SMTP MIME parser in rust/src/mime/smtp.rs …

Sep 18, 2026
CVE-2026-93873
4.3 MEDIUM

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the contact plugin submission handler, allowing attackers to forge messages. Attackers can auto-submit contact forms from …

Sep 18, 2026
CVE-2026-93871
5.4 MEDIUM

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store …

Sep 18, 2026
CVE-2026-93870
4.3 MEDIUM

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers …

Sep 18, 2026
CVE-2026-93869
6.1 MEDIUM

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers …

Sep 18, 2026
CVE-2026-93838
5.9 MEDIUM

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. …

Sep 18, 2026
CVE-2026-91205
6.0 MEDIUM

A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable …

Sep 18, 2026
CVE-2026-91203
6.0 MEDIUM

A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged …

Sep 18, 2026
CVE-2026-91202
6.1 MEDIUM

A flaw was found in cockpit-files. A low-privileged local user can exploit this vulnerability by crafting a directory containing a symbolic link (symlink) and then …

Sep 18, 2026
CVE-2026-82890
5.9 MEDIUM

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary JavaScript code due to improper neutralization of input during web page …

Sep 18, 2026
CVE-2026-81623
6.3 MEDIUM

IBM Guardium Data Protection 12.2 could allow an authenticated user to execute arbitrary commands with low user privileges on the system due to improper validation …

Sep 18, 2026
CVE-2026-77528
5.3 MEDIUM

Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely …

Sep 18, 2026
CVE-2026-76902
5.0 MEDIUM

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and …

Sep 18, 2026
CVE-2026-76901
5.8 MEDIUM

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in …

Sep 18, 2026
CVE-2026-76900
6.8 MEDIUM

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration and …

Sep 18, 2026
CVE-2026-76899
5.7 MEDIUM

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with …

Sep 18, 2026
CVE-2026-61822
6.5 MEDIUM

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows …

Sep 18, 2026
CVE-2026-61723
6.8 MEDIUM

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned …

Sep 18, 2026
CVE-2026-61722
6.8 MEDIUM

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned …

Sep 18, 2026
CVE-2026-61720
6.2 MEDIUM

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size …

Sep 18, 2026
CVE-2026-57224
6.5 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates …

Sep 18, 2026
CVE-2026-57222
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address …

Sep 18, 2026
CVE-2026-52745
5.3 MEDIUM

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller …

Sep 18, 2026
CVE-2026-18869
6.4 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions and access internal network services due to improper …

Sep 18, 2026
CVE-2026-17262
5.4 MEDIUM

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to cause a denial of service due to improper validation of FTP authentication …

Sep 18, 2026
CVE-2026-11722
4.8 MEDIUM

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

Sep 18, 2026
CVE-2026-11711
6.5 MEDIUM

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

Sep 18, 2026
CVE-2026-11710
6.5 MEDIUM

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

Sep 18, 2026
CVE-2026-11549
6.5 MEDIUM

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.

Sep 18, 2026
CVE-2026-11548
4.8 MEDIUM

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

Sep 18, 2026
CVE-2026-11540
5.3 MEDIUM

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

Sep 18, 2026
CVE-2026-11539
5.3 MEDIUM

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

Sep 18, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.