CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-85350
5.3 MEDIUM

The UpsellWP WordPress plugin before 2.2.10 does not check that products added to the cart through a Frequently Bought Together campaign belong to that campaign, …

Sep 18, 2026
CVE-2026-85123
5.3 MEDIUM

The Easy Form Builder by WhiteStudio WordPress plugin before 4.2.0 does not validate a submitted value against the stored configuration for some of its form …

Sep 18, 2026
CVE-2026-85009
6.5 MEDIUM

The RestroPress WordPress plugin through 3.4.6 does not verify ownership in its payment-recovery flow before acting on a request-supplied order identifier, allowing unauthenticated attackers to …

Sep 18, 2026
CVE-2026-84902
6.8 MEDIUM

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users …

Sep 18, 2026
CVE-2026-92991
5.4 MEDIUM

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This …

Sep 18, 2026
CVE-2026-15650
6.4 MEDIUM

The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute …

Sep 18, 2026
CVE-2026-14855
6.4 MEDIUM

The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 …

Sep 18, 2026
CVE-2026-93455
6.5 MEDIUM

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media …

Sep 18, 2026
CVE-2026-93314
6.3 MEDIUM

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can …

Sep 18, 2026
CVE-2026-93313
6.3 MEDIUM

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer …

Sep 18, 2026
CVE-2026-82985
6.5 MEDIUM

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album …

Sep 18, 2026
CVE-2026-82982
4.3 MEDIUM

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a …

Sep 18, 2026
CVE-2026-82980
6.3 MEDIUM

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files …

Sep 18, 2026
CVE-2026-77170
4.3 MEDIUM

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission …

Sep 18, 2026
CVE-2026-77169
6.5 MEDIUM

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level …

Sep 18, 2026
CVE-2026-77164
6.2 MEDIUM

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, …

Sep 18, 2026
CVE-2026-93312
4.3 MEDIUM

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It …

Sep 18, 2026
CVE-2026-93311
4.3 MEDIUM

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of …

Sep 18, 2026
CVE-2026-93310
5.3 MEDIUM

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of …

Sep 18, 2026
CVE-2026-93454
5.4 MEDIUM

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term …

Sep 18, 2026
CVE-2026-93451
6.5 MEDIUM

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass …

Sep 18, 2026
CVE-2026-93309
4.3 MEDIUM

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation …

Sep 18, 2026
CVE-2026-93308
4.3 MEDIUM

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation …

Sep 18, 2026
CVE-2026-2585
6.4 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, …

Sep 18, 2026
CVE-2026-18441
4.3 MEDIUM

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Sep 18, 2026
CVE-2026-55946
6.1 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Sep 17, 2026
CVE-2026-93307
4.3 MEDIUM

A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Collector. Such manipulation of the argument …

Sep 17, 2026
CVE-2026-73638
6.2 MEDIUM

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data …

Sep 17, 2026
CVE-2026-54648
6.5 MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely on page-level CC_PERM_READ access and do not require CC_PERM_DELETE for …

Sep 17, 2026
CVE-2026-54645
4.8 MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, description_short, and spec_copy rich-text fields from $GLOBALS['RAW']['POST'] and removes only script elements …

Sep 17, 2026
CVE-2026-54644
6.1 MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip_tags to permit anchor elements in error, information, and warning …

Sep 17, 2026
CVE-2026-54643
5.4 MEDIUM

CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting …

Sep 17, 2026
CVE-2026-54613
5.4 MEDIUM

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, getThemeFolder() in admin/controller/editor/revisions.php …

Sep 17, 2026
CVE-2026-50291
5.5 MEDIUM

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 …

Sep 17, 2026
CVE-2026-16750
5.3 MEDIUM

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in …

Sep 17, 2026
CVE-2026-16582
5.3 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and …

Sep 17, 2026
CVE-2026-14311
5.4 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing …

Sep 17, 2026
CVE-2026-93395
5.3 MEDIUM

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads …

Sep 17, 2026
CVE-2026-93387
4.3 MEDIUM

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium …

Sep 17, 2026
CVE-2026-93386
5.4 MEDIUM

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML …

Sep 17, 2026
CVE-2026-93385
6.5 MEDIUM

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security …

Sep 17, 2026
CVE-2026-93383
4.3 MEDIUM

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security …

Sep 17, 2026
CVE-2026-93379
4.3 MEDIUM

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security …

Sep 17, 2026
CVE-2026-93376
6.3 MEDIUM

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox …

Sep 17, 2026
CVE-2026-77281
6.5 MEDIUM

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. …

Sep 17, 2026
CVE-2026-67071
6.5 MEDIUM

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a …

Sep 17, 2026
CVE-2026-54918
5.3 MEDIUM

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is …

Sep 17, 2026
CVE-2026-54907
5.3 MEDIUM

Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password …

Sep 17, 2026
CVE-2026-54565
4.7 MEDIUM

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser …

Sep 17, 2026
CVE-2026-54521
6.1 MEDIUM

FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in …

Sep 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.