CVE & CISA-KEV Catalog

384,717 CVEs1,686 actively exploited (KEV)
Active:
  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

    Published 2026-08-24

  • CVSS 5.3 v3·EPSS 0.4%·No fix yet

    The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other users. Fixed February 2026.

    Published 2026-08-21

  • CVSS 5.5 v3·EPSS 0.1%·Fix available

    Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

    Published 2026-08-19

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.

    Published 2026-08-18

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.

    Published 2026-08-18

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of sensitive values in these contexts.

    Published 2026-08-16

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.

    Published 2026-08-13

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.

    Published 2026-08-13

  • CVSS 2.4 v4·EPSS 0.2%·No fix yet

    TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A physically proximate attacker can connect to the UART interface and observe the device boot process and runtime debug output. The disclosed information includes operating system details, software versions, network configuration, filesystem paths, and other implementation and debugging information that may assist an attacker in further compromising the device.

    Published 2026-08-10

  • CVSS 6.5 v3·EPSS 0.2%·No fix yet

    Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.

    Published 2026-08-10

  • CVSS 6.9 v4·EPSS 0.3%·No fix yet

    Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP error messages that expose the full filesystem path of the Kirby installation to unauthenticated API users. This vulnerability affects all Kirby sites that have not disabled the REST API with the 'api' => false option. This issue is fixed in versions 4.9.5 and 5.5.2.

    Published 2026-08-07

  • CVSS 5.3 v4·EPSS 0.3%·No fix yet

    Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. This issue does not permit method invocation, object construction, or arbitrary code execution. This has been fixed by restricting property access in the JEXL sandbox to the intended data types.

    Published 2026-08-07

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

    Published 2026-08-06

  • CVSS 9.1 v3·EPSS 0.4%·No fix yet

    A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.0 before 2.13.8, and from 2.14.0 before 2.14.2.

    Published 2026-08-05

  • CVSS 4.0 v3·EPSS 0.1%·No fix yet

    HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

    Published 2026-07-31

  • CVSS 4.3 v3·EPSS 0.1%·No fix yet

    SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagnostic trace when the trace is activated by a privileged user. An attacker with access to the resulting trace data could obtain identifiers that allow impersonation of legitimate users during their validity period. This leads to high impact on confidentiality. Integrity and availability are not impacted.

    Published 2026-07-28

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

    Published 2026-07-27

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress <= 2.97.6 versions.

    Published 2026-07-27

  • CVSS 7.5 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hotel Booking <= 1.0.0 versions.

    Published 2026-07-27

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.

    Published 2026-07-27

  • CVSS 4.8 v4·EPSS 0.1%·No fix yet

    Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.

    Published 2026-07-27

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could allow for asset discovery by unauthenticated users.

    Published 2026-07-23

  • CVSS 8.6 v3·EPSS 0.4%·No fix yet

    Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.

    Published 2026-07-23

  • CVSS 4.3 v3·EPSS 0.3%·No fix yet

    Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.

    Published 2026-07-23

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

    Published 2026-07-23

  • CVSS 4.3 v3·EPSS 0.3%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby Polylang Pro allows Retrieve Embedded Sensitive Data. This issue affects Polylang: through 3.8.5; Polylang Pro: through 3.8.5.

    Published 2026-07-23

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

    Published 2026-07-23

  • CVSS 7.5 v3·EPSS 0.2%·Fix available

    HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.

    Published 2026-07-21

  • CVSS 4.4 v3·EPSS 0.2%·No fix yet

    A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

    Published 2026-07-16

  • CVSS 6.2 v3·EPSS 0.5%·Fix available

    Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an unauthorized attacker to disclose information locally.

    Published 2026-07-14

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.

    Published 2026-07-13

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.

    Published 2026-07-13

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.

    Published 2026-07-13

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in EDGARROJAS WooCommerce PDF Invoice Builder woo-pdf-invoice-builder allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce PDF Invoice Builder: from n/a through <= 2.0.8.

    Published 2026-07-13

  • CVSS 9.8 v3·EPSS 0.7%·No fix yet

    Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.

    Published 2026-07-06

  • CVSS 5.3 v3·EPSS 0.5%·No fix yet

    The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access any device log file available in the blob storage container.

    Published 2026-07-03

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

    Published 2026-07-02

  • CVSS 7.5 v3·EPSS 0.6%·No fix yet

    phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hashes, internal filenames, and SHA-256 fingerprints.

    Published 2026-06-29

  • CVSS 4.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions.

    Published 2026-06-26

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    Unauthenticated Sensitive Data Exposure in WCBoost &#8211; Products Compare <= 1.1.0 versions.

    Published 2026-06-26

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.

    Published 2026-06-26

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 versions.

    Published 2026-06-26

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.

    Published 2026-06-26

  • CVSS 6.3 v4·EPSS 0.3%·No fix yet

    A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.

    Published 2026-06-16

  • CVSS 7.5 v3·EPSS 0.2%·No fix yet

    Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.

    Published 2026-06-15

  • CVSS 7.5 v3·EPSS 0.4%·No fix yet

    Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.

    Published 2026-06-15

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.