CVE Database

46976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-35153
6.7 MEDIUM

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of …

Apr 17, 2026
CVE-2026-35074
6.7 MEDIUM

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of …

Apr 17, 2026
CVE-2026-35073
6.7 MEDIUM

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of …

Apr 17, 2026
CVE-2026-35072
6.7 MEDIUM

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7.0.0, LTS2025 release versions 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60 contain an improper neutralization of …

Apr 17, 2026
CVE-2026-23779
6.7 MEDIUM

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 …

Apr 17, 2026
CVE-2026-6494
5.3 MEDIUM

A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to …

Apr 17, 2026
CVE-2026-6439
4.4 MEDIUM

The VideoZen plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.1. This is due to insufficient input sanitization …

Apr 17, 2026
CVE-2026-6451
4.3 MEDIUM

The cms-fuer-motorrad-werkstaetten plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.0.0. This is due to missing nonce validation …

Apr 17, 2026
CVE-2026-40002
5.0 MEDIUM

Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for …

Apr 17, 2026
CVE-2026-6441
4.3 MEDIUM

The Canto plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 3.1.1. This is due to the absence of any …

Apr 17, 2026
CVE-2026-5797
5.3 MEDIUM

The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to …

Apr 17, 2026
CVE-2026-6080
6.5 MEDIUM

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to insufficient escaping on …

Apr 17, 2026
CVE-2026-5502
5.3 MEDIUM

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized course content manipulation in versions up to and including …

Apr 17, 2026
CVE-2026-5427
5.3 MEDIUM

The Kubio plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 2.7.2. This is due to insufficient capability checks …

Apr 17, 2026
CVE-2026-5234
5.3 MEDIUM

The LatePoint plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.3.2. The vulnerability exists because the …

Apr 17, 2026
CVE-2026-4853
4.9 MEDIUM

The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Directory Deletion in versions up to and …

Apr 17, 2026
CVE-2026-3330
4.9 MEDIUM

The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate', 'username_search', and 'useremail_search' parameters in all versions …

Apr 17, 2026
CVE-2026-5052
5.3 MEDIUM

Vault’s PKI engine’s ACME validation did not reject local targets when issuing http-01 and tls-alpn-01 challenges. This may lead to these requests being sent to …

Apr 17, 2026
CVE-2026-4666
6.5 MEDIUM

The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($args, EXTR_OVERWRITE)` on user-controlled input in the …

Apr 17, 2026
CVE-2026-5162
6.4 MEDIUM

The Royal Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Instagram Feed widget's 'instagram_follow_text' setting in all versions up …

Apr 17, 2026
CVE-2026-4817
6.5 MEDIUM

The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based Blind SQL Injection via the 'order' and 'orderby' …

Apr 17, 2026
CVE-2026-3488
6.5 MEDIUM

The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability …

Apr 17, 2026
CVE-2026-40922
5.4 MEDIUM

SiYuan is an open-source personal knowledge management system. In versions 3.6.1 through 3.6.3, a prior fix for XSS in bazaar README rendering (incomplete fix for …

Apr 17, 2026
CVE-2026-40265
5.9 MEDIUM

Note Mark is an open-source note-taking application. In versions 0.19.1 and prior, the asset download endpoint at /api/notes/{noteID}/assets/{assetID} is registered without authentication middleware, and the …

Apr 17, 2026
CVE-2026-40260
5.3 MEDIUM

pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who …

Apr 17, 2026
CVE-2026-40255
6.1 MEDIUM

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In @adonisjs/http-server versions prior to 7.8.1 and 8.0.0-next.0 through 8.1.3, and …

Apr 16, 2026
CVE-2026-40253
6.8 MEDIUM

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. In versions 3.26.0 and below, the BER/DER decoding functions in the shared common …

Apr 16, 2026
CVE-2024-58343
4.3 MEDIUM

Vision Helpdesk before 5.7.0 (patched in 5.6.10) allows attackers to read user profiles via modified serialized cookie data to vis_client_id.

Apr 16, 2026
CVE-2026-40249
5.3 MEDIUM

free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT handler for updating Policy …

Apr 16, 2026
CVE-2026-34164
4.9 MEDIUM

Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingService logs the full content of every incoming inbox message at …

Apr 16, 2026
CVE-2026-33472
4.8 MEDIUM

Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an attacker to bypass the …

Apr 16, 2026
CVE-2026-40899
6.5 MEDIUM

DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. …

Apr 16, 2026
CVE-2025-43937
6.6 MEDIUM

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could …

Apr 16, 2026
CVE-2025-43935
4.4 MEDIUM

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit …

Apr 16, 2026
CVE-2026-24749
5.3 MEDIUM

The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-rc1 through 3.1.2, images rendered in templates or …

Apr 16, 2026
CVE-2025-43883
4.1 MEDIUM

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could …

Apr 16, 2026
CVE-2025-36579
5.1 MEDIUM

Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, …

Apr 16, 2026
CVE-2026-37100
6.5 MEDIUM

An issue in the Bluetooth Low Energy (BLE) control interface of the Yamaha SR-B30A sound bar firmware 2.40 (Mobile App: Sound Bar Remote / version: …

Apr 16, 2026
CVE-2026-37346
4.7 MEDIUM

SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=.

Apr 16, 2026
CVE-2026-2840
6.4 MEDIUM

The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all …

Apr 16, 2026
CVE-2026-6410
5.3 MEDIUM

@fastify/static versions 8.0.0 through 9.1.0 allow path traversal when directory listing is enabled via the list option. The dirList.path() function resolves directories outside the configured …

Apr 16, 2026
CVE-2026-4160
5.3 MEDIUM

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference via the …

Apr 16, 2026
CVE-2026-6414
5.9 MEDIUM

@fastify/static versions 8.0.0 through 9.1.0 decode percent-encoded path separators (%2F) before filesystem resolution, while Fastify's router treats them as literal characters. This mismatch allows attackers …

Apr 16, 2026
CVE-2026-3369
5.4 MEDIUM

The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded image title in versions up to, …

Apr 16, 2026
CVE-2025-12624
6.0 MEDIUM

Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously …

Apr 16, 2026
CVE-2025-6024
6.1 MEDIUM

The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by …

Apr 16, 2026
CVE-2024-4867
5.4 MEDIUM

The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to …

Apr 16, 2026
CVE-2024-10242
6.1 MEDIUM

The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads …

Apr 16, 2026
CVE-2025-67711
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025
CVE-2025-67710
6.1 MEDIUM

There is a stored cross site scripting issue in Esri ArcGIS Server 11.4 and earlier on Windows and Linux that in some configurations allows a …

Dec 31, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.