CVE Database

60353+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82125
5.3 MEDIUM

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not correctly verify the ownership or the moderation status of a …

Sep 16, 2026
CVE-2026-82124
5.3 MEDIUM

The Schema & Structured Data for WP & AMP WordPress plugin before 1.66 does not check whether a post is password protected before including its …

Sep 16, 2026
CVE-2026-78474
5.3 MEDIUM

The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated …

Sep 16, 2026
CVE-2026-77702
5.3 MEDIUM

The Eventin WordPress plugin before 4.1.24 does not prevent the token issued to a guest at checkout from being used to change that order's tickets …

Sep 16, 2026
CVE-2026-76559
4.1 MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly validate URLs before requesting them during the import process, allowing users with the …

Sep 16, 2026
CVE-2026-76558
6.8 MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not escape custom field names retrieved from the database before inserting them into the DOM …

Sep 16, 2026
CVE-2026-76557
6.8 MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some import configuration values before using them in SQL statements, …

Sep 16, 2026
CVE-2026-76556
6.8 MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not properly sanitise and escape some export filter values before using them in SQL statements, …

Sep 16, 2026
CVE-2026-76555
6.8 MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it and copying it into a publicly …

Sep 16, 2026
CVE-2026-76553
6.5 MEDIUM

The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from stored, user-supplied data before recursively deleting the directory it …

Sep 16, 2026
CVE-2026-5920
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'shortcode_content' parameter of the bt_bb_shortcode shortcode in all versions up …

Sep 16, 2026
CVE-2026-18555
6.1 MEDIUM

The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the …

Sep 16, 2026
CVE-2026-16588
6.5 MEDIUM

The WP Directory Kit plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.5.4 …

Sep 16, 2026
CVE-2026-11996
6.4 MEDIUM

The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 …

Sep 16, 2026
CVE-2026-11984
5.3 MEDIUM

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 …

Sep 16, 2026
CVE-2026-92247
4.7 MEDIUM

A security vulnerability has been detected in synaptikcms synaptik-cms up to 1.3.4.4. This affects the function rename of the file admin/file-manager.php of the component Admin …

Sep 16, 2026
CVE-2026-92221
4.7 MEDIUM

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.php. Executing a manipulation …

Sep 16, 2026
CVE-2026-92220
5.3 MEDIUM

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_transfer/kv_connector/v1/moriio/moriio_connector.py of the component MoRIIO Acknowledgement Handler. Performing a …

Sep 16, 2026
CVE-2026-86109
6.6 MEDIUM

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used …

Sep 16, 2026
CVE-2026-73450
6.9 MEDIUM

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can …

Sep 16, 2026
CVE-2026-92298
4.8 MEDIUM

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote …

Sep 16, 2026
CVE-2026-92217
6.3 MEDIUM

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This …

Sep 16, 2026
CVE-2026-92216
4.3 MEDIUM

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component …

Sep 16, 2026
CVE-2026-92213
5.5 MEDIUM

A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing …

Sep 16, 2026
CVE-2026-92184
6.3 MEDIUM

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The …

Sep 16, 2026
CVE-2026-73460
6.1 MEDIUM

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause …

Sep 16, 2026
CVE-2025-11395
5.5 MEDIUM

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on …

Sep 15, 2026
CVE-2026-92259
5.5 MEDIUM

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and …

Sep 15, 2026
CVE-2026-92257
5.4 MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and …

Sep 15, 2026
CVE-2026-92256
6.5 MEDIUM

NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPsec PSK …

Sep 15, 2026
CVE-2026-92255
5.4 MEDIUM

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated …

Sep 15, 2026
CVE-2026-92114
5.3 MEDIUM

A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such …

Sep 15, 2026
CVE-2026-82567
6.3 MEDIUM

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over …

Sep 15, 2026
CVE-2026-76873
5.2 MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in the DHCP dynamic IP display and ARP bind list display components handling hostname fields. …

Sep 15, 2026
CVE-2026-76872
5.4 MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in DHCP static IP and IP ACL management pages, including dhcp_add_staticip_cgi, dhcp_staticip_show_cgi, ip_acl_set_cgi, and ip_acl_show_cgi. …

Sep 15, 2026
CVE-2026-76871
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and …

Sep 15, 2026
CVE-2026-76868
4.9 MEDIUM

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port …

Sep 15, 2026
CVE-2026-76867
5.4 MEDIUM

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers …

Sep 15, 2026
CVE-2026-76865
4.9 MEDIUM

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An …

Sep 15, 2026
CVE-2026-76864
4.8 MEDIUM

NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers. An attacker can …

Sep 15, 2026
CVE-2026-76863
4.3 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can …

Sep 15, 2026
CVE-2026-76859
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to …

Sep 15, 2026
CVE-2026-76858
4.8 MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script …

Sep 15, 2026
CVE-2026-76857
6.5 MEDIUM

Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach …

Sep 15, 2026
CVE-2026-76855
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit …

Sep 15, 2026
CVE-2026-76854
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal …

Sep 15, 2026
CVE-2026-73444
4.7 MEDIUM

On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment …

Sep 15, 2026
CVE-2026-92237
6.5 MEDIUM

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with …

Sep 15, 2026
CVE-2026-92234
5.4 MEDIUM

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who …

Sep 15, 2026
CVE-2026-91746
4.3 MEDIUM

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.