CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-40536
4.3 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and …

Sep 18, 2026
CVE-2026-40535
6.5 MEDIUM

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and …

Sep 18, 2026
CVE-2026-40534
5.4 MEDIUM

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 …

Sep 18, 2026
CVE-2026-40533
5.3 MEDIUM

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers …

Sep 18, 2026
CVE-2026-40532
6.5 MEDIUM

A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain …

Sep 18, 2026
CVE-2026-40531
4.3 MEDIUM

An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to conduct …

Sep 18, 2026
CVE-2026-21848
5.0 MEDIUM

HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticated attacker to exploit improper access controls, enabling the unauthorized …

Sep 18, 2026
CVE-2026-21822
6.3 MEDIUM

HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handling of file paths allows an authenticated attacker to read …

Sep 18, 2026
CVE-2026-13635
5.3 MEDIUM

An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers …

Sep 18, 2026
CVE-2026-13623
4.8 MEDIUM

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and …

Sep 18, 2026
CVE-2025-13533
4.4 MEDIUM

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 12.0.6 via the Assignment …

Sep 18, 2026
CVE-2026-93493
5.9 MEDIUM

A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that …

Sep 18, 2026
CVE-2026-92622
6.4 MEDIUM

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due …

Sep 18, 2026
CVE-2026-92554
6.1 MEDIUM

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all …

Sep 18, 2026
CVE-2026-92249
6.1 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, …

Sep 18, 2026
CVE-2026-90981
6.1 MEDIUM

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up …

Sep 18, 2026
CVE-2026-85652
6.5 MEDIUM

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions …

Sep 18, 2026
CVE-2026-75961
4.9 MEDIUM

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up …

Sep 18, 2026
CVE-2026-17607
6.5 MEDIUM

The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, …

Sep 18, 2026
CVE-2026-17586
6.4 MEDIUM

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, …

Sep 18, 2026
CVE-2026-16777
4.9 MEDIUM

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, …

Sep 18, 2026
CVE-2026-15004
5.4 MEDIUM

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all …

Sep 18, 2026
CVE-2026-14472
6.4 MEDIUM

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, …

Sep 18, 2026
CVE-2026-13471
4.3 MEDIUM

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, …

Sep 18, 2026
CVE-2026-12739
4.3 MEDIUM

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Sep 18, 2026
CVE-2026-11757
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue …

Sep 18, 2026
CVE-2026-92714
6.5 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked …

Sep 18, 2026
CVE-2026-92561
6.1 MEDIUM

The Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'options' parameter in all versions up to, and including, 11.8.2 due …

Sep 18, 2026
CVE-2026-91707
5.3 MEDIUM

The The Divi theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.11.1. This is due to the …

Sep 18, 2026
CVE-2026-90977
5.3 MEDIUM

The Clean Login WordPress plugin before 1.19 does not verify its registration CAPTCHA when the stored session value is empty, allowing unauthenticated users to bypass …

Sep 18, 2026
CVE-2026-90976
5.3 MEDIUM

The Clean Login WordPress plugin before 1.19 does not check whether user registration is enabled before creating an account in its registration handler, allowing unauthenticated …

Sep 18, 2026
CVE-2026-89330
6.1 MEDIUM

The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Reflected Cross-Site …

Sep 18, 2026
CVE-2026-89278
5.3 MEDIUM

The GPTranslate – Multilingual AI Translation Agent for WordPress: Translate Your Site with AI plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

Sep 18, 2026
CVE-2026-89138
4.3 MEDIUM

The Filter Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin …

Sep 18, 2026
CVE-2026-88994
6.6 MEDIUM

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included …

Sep 18, 2026
CVE-2026-86800
5.3 MEDIUM

The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, …

Sep 18, 2026
CVE-2026-86796
5.3 MEDIUM

The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection …

Sep 18, 2026
CVE-2026-84909
6.4 MEDIUM

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'buttoncolor' Shortcode Attribute …

Sep 18, 2026
CVE-2026-79713
6.5 MEDIUM

The Breeze Cache WordPress plugin before 2.5.15 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested …

Sep 18, 2026
CVE-2026-75017
4.3 MEDIUM

The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to authorization …

Sep 18, 2026
CVE-2026-75016
6.4 MEDIUM

The Magazine Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the News Ticker block's clientId attribute in versions up to, and including, …

Sep 18, 2026
CVE-2026-18317
4.3 MEDIUM

The Foxtool All-in-One: Contact chat button, Custom login, Media optimize images plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Sep 18, 2026
CVE-2026-17576
6.5 MEDIUM

The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection via the get_comments action in versions up to, and including, 1.13.9. This is due …

Sep 18, 2026
CVE-2026-12106
6.4 MEDIUM

The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage …

Sep 18, 2026
CVE-2024-38639
4.8 MEDIUM

An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system. …

Sep 18, 2026
CVE-2026-90984
5.8 MEDIUM

The Generate PDF using Contact Form 7 WordPress plugin before 4.2.2 does not restrict the destination of the image fetch its PDF renderer performs on …

Sep 18, 2026
CVE-2026-88993
6.8 MEDIUM

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with …

Sep 18, 2026
CVE-2026-88798
5.3 MEDIUM

The Really Simple Security WordPress plugin before 9.8.3 does not validate a client-supplied address value before using it as a storage key in one of …

Sep 18, 2026
CVE-2026-87966
5.3 MEDIUM

The Easy Appointments WordPress plugin before 4.0.2.2 does not perform an ownership or authorization check on its unauthenticated appointment-reservation endpoint before updating an existing appointment …

Sep 18, 2026
CVE-2026-87965
4.8 MEDIUM

The Easy Appointments WordPress plugin before 4.0.2.2 does not use an unguessable token to authorize its mail-link appointment cancellation and confirmation action, deriving the token …

Sep 18, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.