CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-59193
4.9 MEDIUM

Grav is a file-based Web platform. Prior to 2.0.0, an authenticated admin.super user can crash Grav or fill the disk by uploading a specially crafted …

Jul 10, 2026
CVE-2026-59154
4.3 MEDIUM

Wekan is open source kanban built with Meteor. Prior to 9.64, Wekan has a cross-board authorization bypass in the direct Meteor collection allow rules for …

Jul 10, 2026
CVE-2026-55890
4.8 MEDIUM

Grav is a file-based Web platform. Prior to 2.0.0-rc.9, Grav's incomplete fix for stored XSS through the Markdown media attribute action (CVE-2026-42841) leaves the sibling …

Jul 10, 2026
CVE-2026-55885
6.8 MEDIUM

Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation …

Jul 10, 2026
CVE-2026-55669
4.2 MEDIUM

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validates a token's signature and issuer (iss) …

Jul 10, 2026
CVE-2026-3251
6.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum allows Stored XSS. This issue affects Mezunum …

Jul 10, 2026
CVE-2026-15377
4.3 MEDIUM

A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown functionality of the file /callrec/sendlogfile. This manipulation causes …

Jul 10, 2026
CVE-2026-15376
6.3 MEDIUM

A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The manipulation results in improper authorization. …

Jul 10, 2026
CVE-2026-8609
5.3 MEDIUM

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the …

Jul 10, 2026
CVE-2026-8595
6.8 MEDIUM

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the …

Jul 10, 2026
CVE-2026-46388
4.4 MEDIUM

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery …

Jul 10, 2026
CVE-2026-15375
4.3 MEDIUM

A vulnerability has been found in Eleveo Call Recording Software 9.7.0. This impacts an unknown function of the file /callrec/users_ldap.jsp of the component LDAP User …

Jul 10, 2026
CVE-2026-15374
6.3 MEDIUM

A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the component Group Interface. …

Jul 10, 2026
CVE-2026-15373
6.3 MEDIUM

A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.do. Performing a manipulation of …

Jul 10, 2026
CVE-2026-61456
4.6 MEDIUM

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1/media endpoint. The HandlesMediaUploads::processUploadedFile() method validates only the file …

Jul 10, 2026
CVE-2026-61455
6.5 MEDIUM

Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesting depth. Attackers can supply a …

Jul 10, 2026
CVE-2026-61450
6.5 MEDIUM

Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrate …

Jul 10, 2026
CVE-2026-61441
6.5 MEDIUM

PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete …

Jul 10, 2026
CVE-2026-61432
5.7 MEDIUM

PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither …

Jul 10, 2026
CVE-2026-61431
5.5 MEDIUM

PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute …

Jul 10, 2026
CVE-2026-60089
5.5 MEDIUM

PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A …

Jul 10, 2026
CVE-2026-60086
5.3 MEDIUM

PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector …

Jul 10, 2026
CVE-2026-58661
4.3 MEDIUM

n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The per-request quota …

Jul 10, 2026
CVE-2026-57994
5.3 MEDIUM

phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated attackers to retrieve inactive (draft or review-only) FAQ …

Jul 10, 2026
CVE-2026-56354
4.1 MEDIUM

n8n before 1.123.24, 2.10.4, and 2.12.0 (across its 1.x and 2.x branches) contains cross-site scripting and open redirect vulnerabilities in the Form Node due to …

Jul 10, 2026
CVE-2026-56335
6.5 MEDIUM

Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null …

Jul 10, 2026
CVE-2026-56329
6.4 MEDIUM

Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can …

Jul 10, 2026
CVE-2026-56312
6.5 MEDIUM

Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha …

Jul 10, 2026
CVE-2026-56309
5.4 MEDIUM

Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary …

Jul 10, 2026
CVE-2026-54470
5.3 MEDIUM

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access …

Jul 10, 2026
CVE-2026-54468
6.5 MEDIUM

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability …

Jul 10, 2026
CVE-2026-9857
4.3 MEDIUM

The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not …

Jul 10, 2026
CVE-2026-13710
6.4 MEDIUM

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 10, 2026
CVE-2026-13247
6.4 MEDIUM

The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jul 10, 2026
CVE-2026-13010
6.5 MEDIUM

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortcode Attribute …

Jul 10, 2026
CVE-2026-12918
4.9 MEDIUM

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter …

Jul 10, 2026
CVE-2026-11990
5.3 MEDIUM

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. …

Jul 10, 2026
CVE-2026-9838
6.1 MEDIUM

The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due …

Jul 10, 2026
CVE-2026-6802
5.3 MEDIUM

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due …

Jul 10, 2026
CVE-2026-6440
4.3 MEDIUM

The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to …

Jul 10, 2026
CVE-2026-3907
6.4 MEDIUM

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.1.7. This is …

Jul 10, 2026
CVE-2026-1946
4.3 MEDIUM

The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function …

Jul 10, 2026
CVE-2026-15104
6.5 MEDIUM

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the 'lang' parameter …

Jul 10, 2026
CVE-2026-15026
4.3 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via …

Jul 10, 2026
CVE-2026-14475
4.9 MEDIUM

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection via the 'scan_id' parameter in …

Jul 10, 2026
CVE-2026-12955
4.3 MEDIUM

The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on …

Jul 10, 2026
CVE-2026-12924
6.4 MEDIUM

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'etn_faq_content' parameter …

Jul 10, 2026
CVE-2026-12400
4.3 MEDIUM

The FlowForms – Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.1 via …

Jul 10, 2026
CVE-2026-12108
4.4 MEDIUM

The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due …

Jul 10, 2026
CVE-2026-11992
4.3 MEDIUM

The Easy Appointments plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.12.27. This is due to the plugin …

Jul 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.