CVE Database

48111+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-92942
7.5 HIGH

vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout …

Sep 17, 2026
CVE-2026-90986
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.

Sep 17, 2026
CVE-2026-90887
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.

Sep 17, 2026
CVE-2026-81442
8.1 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this …

Sep 17, 2026
CVE-2026-78295
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.

Sep 17, 2026
CVE-2026-66631
7.6 HIGH

Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.

Sep 17, 2026
CVE-2026-66630
7.6 HIGH

Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.

Sep 17, 2026
CVE-2026-66628
7.6 HIGH

Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.

Sep 17, 2026
CVE-2026-66626
7.6 HIGH

Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.

Sep 17, 2026
CVE-2026-66625
7.6 HIGH

Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.

Sep 17, 2026
CVE-2026-66624
7.6 HIGH

Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.

Sep 17, 2026
CVE-2026-66619
7.6 HIGH

Administrator SQL Injection in Newsletters <= 4.18 versions.

Sep 17, 2026
CVE-2026-66618
7.6 HIGH

Administrator SQL Injection in WP Maps <= 4.9.9 versions.

Sep 17, 2026
CVE-2026-66580
8.5 HIGH

Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.

Sep 17, 2026
CVE-2026-66571
7.1 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

Sep 17, 2026
CVE-2026-92919
8.1 HIGH

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. …

Sep 17, 2026
CVE-2026-92918
8.8 HIGH

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the …

Sep 17, 2026
CVE-2026-81481
7.5 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker …

Sep 17, 2026
CVE-2026-92925
7.1 HIGH

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying …

Sep 17, 2026
CVE-2026-92917
7.5 HIGH

Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, …

Sep 17, 2026
CVE-2026-92916
7.5 HIGH

Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the …

Sep 17, 2026
CVE-2026-92915
7.3 HIGH

WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = …

Sep 17, 2026
CVE-2026-92914
8.1 HIGH

AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. …

Sep 17, 2026
CVE-2026-92913
7.4 HIGH

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code …

Sep 17, 2026
CVE-2026-81480
7.2 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this …

Sep 17, 2026
CVE-2026-81478
8.1 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit …

Sep 17, 2026
CVE-2026-81477
7.2 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this …

Sep 17, 2026
CVE-2026-81476
8.1 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An …

Sep 17, 2026
CVE-2026-81475
8.1 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit …

Sep 17, 2026
CVE-2026-81440
7.3 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Sep 17, 2026
CVE-2026-92903
8.2 HIGH

Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement …

Sep 17, 2026
CVE-2026-81474
7.8 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this …

Sep 17, 2026
CVE-2026-66269
7.3 HIGH

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker …

Sep 17, 2026
CVE-2026-78428
8.0 HIGH

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login …

Sep 17, 2026
CVE-2026-86320
7.8 HIGH

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a …

Sep 17, 2026
CVE-2026-87963
8.6 HIGH

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and …

Sep 17, 2026
CVE-2026-86801
8.8 HIGH

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no …

Sep 17, 2026
CVE-2026-91014
7.1 HIGH

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them …

Sep 17, 2026
CVE-2026-88904
8.8 HIGH

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken …

Sep 17, 2026
CVE-2026-88792
8.8 HIGH

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to …

Sep 17, 2026
CVE-2026-87786
8.8 HIGH

The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users …

Sep 17, 2026
CVE-2026-85130
8.8 HIGH

The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later …

Sep 17, 2026
CVE-2026-85128
7.5 HIGH

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to …

Sep 17, 2026
CVE-2025-15697
7.1 HIGH

The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated …

Sep 17, 2026
CVE-2026-87935
8.1 HIGH

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This …

Sep 17, 2026
CVE-2026-25294
7.4 HIGH

Transient DOS while parsing frame during channel usage.

Sep 17, 2026
CVE-2026-25290
7.8 HIGH

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

Sep 17, 2026
CVE-2026-25284
7.3 HIGH

Information Disclosure when a pointer is reused after being deallocated.

Sep 17, 2026
CVE-2026-25283
8.8 HIGH

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Sep 17, 2026
CVE-2026-25282
7.9 HIGH

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

Sep 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.