60139+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability in the csi-powerflex; csi-powermax; csi-powerstore. An unauthenticated attacker with …
Dell Container Storage Modules, versions prior to 1.18.0, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access …
A security flaw has been discovered in vllm-project vLLM up to 0.31.0. This impacts the function get_token_bin_counts_and_mask of the file vllm/model_executor/layers/utils.py of the component Penalty …
A vulnerability was identified in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. This affects an unknown function of the file search_class.php. Such manipulation of the argument school_year …
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the /api/task_result/{task_name} endpoint calls SessionManager.get_result_by_task() in ufo/server/services/session_manager.py, which acquires …
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.forms.models.BaseModelFormSet.save_existing_objects()` used the presence of a primary key on …
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. An incomplete fix for CVE-2026-15307 in Django spatial lookups …
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.http.parse_header_parameters()` was subject to a potential denial-of-service attack due …
Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects …
An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when …
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akıllı Ticaret Software Technologies Ltd. Co. E-Commerce Pack allows Reflected XSS. This issue …
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to inject completed LOCAL_DISK replicas through the NotifyOffloadSuccess RPC. Attackers can …
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to create, steal, and falsely complete replication tasks via the coro_rpc …
lrzsz before 0.13.0 contains a heap-based buffer overflow vulnerability in procheader() of the lrz receive utility when copying overlong sender-supplied filenames into Pathname. Malicious ZMODEM …
libmikmod before 3.3.14 contains a heap out-of-bounds read vulnerability in the Impulse Tracker loader load_it.c that allows attackers to read adjacent heap memory via oversized …
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, authenticated device registration through /api/devices can supply a permitted …
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq …
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign …
Rundeck before 6.2.0 contains a path traversal vulnerability that allows users holding only the project configure ACL to read arbitrary server files by setting resources.source.N.config.file …
Unauthenticated Bypass Vulnerability in Login Lockdown <= 2.17 versions.
Unauthenticated Settings Change in PayPlug for WooCommerce (Official) <= 3.1.0 versions.
Unauthenticated Settings Change in TrueBooker <= 1.2.9 versions.
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
Subscriber Cross Site Scripting (XSS) in Front End PM <= 11.4.6 versions.
Unauthenticated Broken Access Control in 10Web Social Photo Feed <= 1.4.35 versions.
Unauthenticated Bypass Vulnerability in Captcha by BestWebSoft <= 5.2.8 versions.
Subscriber Denial of Service Attack in WPBase Cache <= 5.5.6 versions.
Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects …
Unauthenticated Insecure Direct Object References (IDOR) in Wappointment <= 2.7.7 versions.
Contributor Arbitrary File Download in Piotnet Addons For Elementor <= 7.1.71 versions.
Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions.
Subscriber Cross Site Scripting (XSS) in WC Fields Factory <= 4.1.12 versions.
Subscriber Cross Site Scripting (XSS) in Ohio Extra <= 3.6.8 versions.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: …
A vulnerability was identified in SourceCodester Simple Student Information System 1.0. This issue affects some unknown processing of the file /register.php of the component Profile …
Subscriber Broken Access Control in Delete All Comments of wordpress <= 7.1 versions.
Unauthenticated Bypass Vulnerability in Zero Spam <= 5.7.11 versions.
Unauthenticated Broken Authentication in Advanced Google reCAPTCHA <= 5.40 versions.
A flaw was found in the OIDC implementation of Keycloak, specifically within the Device Authorization Grant flow. This component allows devices with limited input capabilities …
The elegro Crypto Payment WordPress plugin through 1.0.1 does not require a shared secret to be configured before trusting incoming payment notification requests, allowing unauthenticated …
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any …
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the payment with the payment provider when handling the return from the hosted checkout, …
The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify the authenticity of incoming payment provider notifications, and ships with that verification disabled by …
The Fast Courier WordPress plugin through 5.2.3 does not restrict an unauthenticated REST route that writes order fulfillment data, allowing unauthenticated attackers to overwrite the …
The Slider Pro WordPress plugin through 1.0.0 does not perform any capability or authorisation check on one of its AJAX actions, allowing unauthenticated users to …
Memory Corruption when processing concurrent DMA buffer allocation and deallocation commands without proper synchronization.
Memory Corruption when processing camera operations due to out-of-bounds write during driver updates.
Memory Corruption when processing camera CRE driver operations with improper handling of buffer limits during hardware update preparation.
Memory corruption when processing command buffer requests with invalid length parameters in the Android Camera driver.
Memory corruption when processing camera requests with excessive batch and IO buffer configurations exceeds allocated memory size.
Free website and port scanning — find vulnerabilities before attackers do.