CVE Database

47974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-104406
7.3 HIGH

Unauthenticated Broken Access Control in picu <= 3.10.1 versions.

Oct 6, 2026
CVE-2026-104405
8.1 HIGH

Unauthenticated Privilege Escalation in GiveWP <= 4.17.0 versions.

Oct 6, 2026
CVE-2026-104395
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in picu <= 3.10.1 versions.

Oct 6, 2026
CVE-2026-104394
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Charitable <= 1.8.12.3 versions.

Oct 6, 2026
CVE-2026-104387
7.2 HIGH

Unauthenticated Broken Access Control in PowerPress Podcasting <= 11.17.9 versions.

Oct 6, 2026
CVE-2026-104385
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Groundhogg <= 4.8.3 versions.

Oct 6, 2026
CVE-2026-103346
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tomlister Payflex Payment Gateway payflex-payment-gateway allows Reflected XSS.This issue affects Payflex Payment Gateway: …

Oct 6, 2026
CVE-2026-102915
8.5 HIGH

Subscriber Broken Access Control in WPO365 <= 44.1 versions.

Oct 6, 2026
CVE-2026-102387
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Xserver Migrator <= 1.6.6 versions.

Oct 6, 2026
CVE-2026-105807
7.3 HIGH

A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in …

Oct 6, 2026
CVE-2026-57559
7.8 HIGH

Memory corruption while processing service requests.

Oct 6, 2026
CVE-2026-57555
7.8 HIGH

Memory Corruption when executing system service routines due to improper handling of user input buffers.

Oct 6, 2026
CVE-2026-57554
7.8 HIGH

Memory Corruption when asynchronous threads access shared performance counter data simultaneously during FastRPC invocations.

Oct 6, 2026
CVE-2026-57546
7.5 HIGH

Transient DOS when processing a continuous receive command with a zero-sized global configuration override.

Oct 6, 2026
CVE-2026-57545
7.8 HIGH

Memory corruption when processing draw objects of incorrect type during graphics command list execution.

Oct 6, 2026
CVE-2026-57537
7.8 HIGH

Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.

Oct 6, 2026
CVE-2026-25302
7.1 HIGH

Cryptographic Issue when processing non-ELF partitions, authentication and signature checks are bypassed, allowing unsigned or corrupted images to be mounted and processed.

Oct 6, 2026
CVE-2026-25291
7.8 HIGH

Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.

Oct 6, 2026
CVE-2026-25267
7.8 HIGH

Memory corruption when non-secure loader rewrites page tables before secure memory initialization.

Oct 6, 2026
CVE-2026-105776
7.3 HIGH

A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation …

Oct 6, 2026
CVE-2026-105701
8.8 HIGH

The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This …

Oct 6, 2026
CVE-2026-75962
7.2 HIGH

The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to …

Oct 6, 2026
CVE-2026-41563
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.

Oct 6, 2026
CVE-2026-41558
7.5 HIGH

Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.

Oct 6, 2026
CVE-2026-39789
7.5 HIGH

Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.

Oct 6, 2026
CVE-2026-39760
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.

Oct 6, 2026
CVE-2026-39723
7.5 HIGH

Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.

Oct 6, 2026
CVE-2026-105072
7.5 HIGH

Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.

Oct 6, 2026
CVE-2026-105704
7.3 HIGH

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument …

Oct 6, 2026
CVE-2026-105571
7.3 HIGH

A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component …

Oct 6, 2026
CVE-2026-105486
7.3 HIGH

A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing …

Oct 6, 2026
CVE-2026-82988
7.5 HIGH

There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation …

Oct 6, 2026
CVE-2026-105783
8.0 HIGH

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with …

Oct 6, 2026
CVE-2026-105782
7.5 HIGH

Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled …

Oct 6, 2026
CVE-2026-105762
8.3 HIGH

Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the …

Oct 6, 2026
CVE-2026-105471
7.3 HIGH

A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration …

Oct 6, 2026
CVE-2026-105761
7.1 HIGH

Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;app_id&gt;/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the …

Oct 5, 2026
CVE-2026-105470
7.3 HIGH

A vulnerability was identified in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This issue affects the function mysqli_query of the file locateus.php of the component Doctor Search …

Oct 5, 2026
CVE-2026-105469
7.3 HIGH

A vulnerability was determined in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This vulnerability affects unknown code of the file get_town.php of the component AJAX Endpoint. Executing …

Oct 5, 2026
CVE-2026-105744
7.5 HIGH

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") …

Oct 5, 2026
CVE-2026-105468
7.3 HIGH

A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function mysqli_query of the file Admin/mlogin.php of the component Login Handler. Performing …

Oct 5, 2026
CVE-2026-77226
8.1 HIGH

Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource incorrectly determines setup availability by counting …

Oct 5, 2026
CVE-2026-105773
7.0 HIGH

Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient …

Oct 5, 2026
CVE-2026-105741
7.1 HIGH

Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.5.0 until 1.10.3, an IP spoofing vulnerability in the Model Context Protocol …

Oct 5, 2026
CVE-2026-102262
7.3 HIGH

Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious …

Oct 5, 2026
CVE-2026-97257
8.8 HIGH

Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.

Oct 5, 2026
CVE-2026-95265
7.5 HIGH

Feehi CMS 2.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the UEditor catchimage endpoint. The private-IP validation does not block loopback or link-local addresses, …

Oct 5, 2026
CVE-2026-95263
7.2 HIGH

Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator …

Oct 5, 2026
CVE-2026-93617
7.2 HIGH

Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.

Oct 5, 2026
CVE-2026-78861
7.7 HIGH

An issue in Mercusys AC12 V2 allows a local attacker to execute arbitrary code via a hardcoded 512-bit RSA Private Key

Oct 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.