CVE Vulnerability Database

Search and browse 389,984 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-61429HIGH8.5PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th...
CVE-2026-61428HIGH7.3PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attacke...
CVE-2026-61426HIGH8.8PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requireme...
CVE-2026-60090CRITICAL9.8PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowled...
CVE-2026-60088MEDIUM6.8PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read f...
CVE-2026-56763MEDIUM6.3Hono before 4.12.7 allows __proto__ key in parseBody with dot option enabled, permitting specially crafted form field na...
CVE-2026-56372CRITICAL9.1ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers...
CVE-2026-56303HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function m...
CVE-2026-56296MEDIUM6.9Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that ret...
CVE-2026-56240MEDIUM5.3Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows o...
CVE-2026-57828HIGH8.8Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoc...
CVE-2026-57827CRITICAL9.8Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFi...
CVE-2026-1359HIGH8.8The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2026-9282HIGH7.5The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4...
CVE-2026-9017MEDIUM5.3The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all ve...
CVE-2026-6939HIGH7.2The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app...
CVE-2026-6801MEDIUM5.3The Context Blog theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2026-4661HIGH7.5The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQ...
CVE-2026-1382MEDIUM6.4The fresh Podcaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'freshpodcaster' shortcode...
CVE-2026-15155HIGH8.8The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Authent...
CVE-2026-15010MEDIUM6.4The bbp Style Pack plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6...
CVE-2026-12994MEDIUM5.3The WCFM – Frontend Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions u...
CVE-2026-12738MEDIUM4.3The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypas...
CVE-2026-12126MEDIUM6.4The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-12103MEDIUM4.3The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi...