Published vulnerability pages

Website Security Risk Index — Page 32

Current vulnerabilities, affected platforms, and fix guidance for website owners and developers.

Browse by topic

Security risk categories

46 categories with published guidance

Memory Corruption

409

Browse published Memory Corruption vulnerabilities, affected products, and practical fix guidance.

Authorization Bypass

373

Browse published Authorization Bypass vulnerabilities, affected products, and practical fix guidance.

WordPress

350

Browse published WordPress vulnerabilities, affected products, and practical fix guidance.

Information Disclosure

320

Browse published Information Disclosure vulnerabilities, affected products, and practical fix guidance.

Remote Code Execution

303

Browse published Remote Code Execution vulnerabilities, affected products, and practical fix guidance.

Cross-site Scripting

260

Browse published Cross-site Scripting vulnerabilities, affected products, and practical fix guidance.

Network Security

253

Browse published Network Security vulnerabilities, affected products, and practical fix guidance.

Input Validation

243

Browse published Input Validation vulnerabilities, affected products, and practical fix guidance.

Web Application

239

Browse published Web Application vulnerabilities, affected products, and practical fix guidance.

Windows

216

Browse published Windows vulnerabilities, affected products, and practical fix guidance.

API Security

215

Browse published API Security vulnerabilities, affected products, and practical fix guidance.

Browser

215

Browse published Browser vulnerabilities, affected products, and practical fix guidance.

Denial of Service

215

Browse published Denial of Service vulnerabilities, affected products, and practical fix guidance.

Microsoft

212

Browse published Microsoft vulnerabilities, affected products, and practical fix guidance.

PHP

199

Browse published PHP vulnerabilities, affected products, and practical fix guidance.

Path Traversal

167

Browse published Path Traversal vulnerabilities, affected products, and practical fix guidance.

Authentication Bypass

118

Browse published Authentication Bypass vulnerabilities, affected products, and practical fix guidance.

Arbitrary File Write

116

Browse published Arbitrary File Write vulnerabilities, affected products, and practical fix guidance.

Privilege Escalation

113

Browse published Privilege Escalation vulnerabilities, affected products, and practical fix guidance.

Linux

94

Browse published Linux vulnerabilities, affected products, and practical fix guidance.

DevOps

81

Browse published DevOps vulnerabilities, affected products, and practical fix guidance.

SQL Injection

72

Browse published SQL Injection vulnerabilities, affected products, and practical fix guidance.

Cryptography

68

Browse published Cryptography vulnerabilities, affected products, and practical fix guidance.

SSRF

61

Browse published SSRF vulnerabilities, affected products, and practical fix guidance.

Python

59

Browse published Python vulnerabilities, affected products, and practical fix guidance.

Java

57

Browse published Java vulnerabilities, affected products, and practical fix guidance.

IDOR

56

Browse published IDOR vulnerabilities, affected products, and practical fix guidance.

WooCommerce

53

Browse published WooCommerce vulnerabilities, affected products, and practical fix guidance.

Unsafe Deserialization

51

Browse published Unsafe Deserialization vulnerabilities, affected products, and practical fix guidance.

File Upload

47

Browse published File Upload vulnerabilities, affected products, and practical fix guidance.

npm

44

Browse published npm vulnerabilities, affected products, and practical fix guidance.

Joomla

41

Browse published Joomla vulnerabilities, affected products, and practical fix guidance.

Supply Chain

39

Browse published Supply Chain vulnerabilities, affected products, and practical fix guidance.

Cloud Security

36

Browse published Cloud Security vulnerabilities, affected products, and practical fix guidance.

CSRF

33

Browse published CSRF vulnerabilities, affected products, and practical fix guidance.

Race Condition

31

Browse published Race Condition vulnerabilities, affected products, and practical fix guidance.

PDF Editor

28

Browse published PDF Editor vulnerabilities, affected products, and practical fix guidance.

Industrial Control

27

Browse published Industrial Control vulnerabilities, affected products, and practical fix guidance.

.NET

23

Browse published .NET vulnerabilities, affected products, and practical fix guidance.

File Deletion

23

Browse published File Deletion vulnerabilities, affected products, and practical fix guidance.

Open Redirect

16

Browse published Open Redirect vulnerabilities, affected products, and practical fix guidance.

Node.js

15

Browse published Node.js vulnerabilities, affected products, and practical fix guidance.

SAML

13

Browse published SAML vulnerabilities, affected products, and practical fix guidance.

Virtualization

13

Browse published Virtualization vulnerabilities, affected products, and practical fix guidance.

Drupal

6

Browse published Drupal vulnerabilities, affected products, and practical fix guidance.

Unix Domain Sockets

5

Browse published Unix Domain Sockets vulnerabilities, affected products, and practical fix guidance.

Published security risks

Showing 1117–1152 of 2230 published risks.

highEPSS 0.001

ICS Calendar <= 12.1.1 - Unauthenticated Stored Cross-Site Scripting

ICS Calendar has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-59516wordpressbrowserxss

Updated Jul 15, 2026

highEPSS 0.002

WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce <= 4.7.4 - Authenticated (Subscriber+) SQL Injection

WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce has a SQL injection issue. An attacker with the needed access can change a request and may read database data.

CVE-2026-57810wordpresswoocommercenetwork-securitysql-injection

Updated Jul 15, 2026

highEPSS 0.002

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution <= 3.1.7 - Unauthenticated Stored Cross-Site Scripting

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57715wordpressbrowserxss

Updated Jul 15, 2026

medium

SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion

SAML Single Sign On – SSO Login has a login security issue. In some setups, an attacker may be able to bypass SAML login checks.

CVE-2026-15013wordpressauthentication-bypasssaml

Updated Jul 15, 2026

criticalEPSS 0.004

777 <= 1.13.0 - Unauthenticated PHP Object Injection

777 has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.

CVE-2026-57738wordpressphpfile-writefile-deletion

Updated Jul 15, 2026

highEPSS 0.002

WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.29 - Unauthenticated Stored Cross-Site Scripting

WPZOOM Portfolio Lite – Filterable Portfolio Plugin has a cross-site scripting issue. Unsafe script can run in another user's browser if the vulnerable feature is used.

CVE-2026-57712wordpressbrowserxss

Updated Jul 15, 2026

criticalEPSS 0.004

CVE-2026-56271 in Flowise

Flowise can fall back to hardcoded JWT secrets, which lets an attacker forge login tokens and act as any user, including an admin.

CVE-2026-56271node-jsnpmauthentication-bypasscryptography

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-58596 in Microsoft Edge Chromium

Microsoft Edge Chromium has an untrusted pointer dereference issue that can let an attacker gain elevated access over the network.

CVE-2026-58596browserlinuxwindowsmicrosoft

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8085 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in model.exe that can run code if a user opens a malicious file.

CVE-2026-8085windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8312 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in expmt.exe that can run code if a user opens a malicious file.

CVE-2026-8312windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8313 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in linker.exe that can run code if a user opens a malicious file.

CVE-2026-8313windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.001

CVE-2026-8314 in Rockwell Automation Arena Simulation

Arena Simulation has an out-of-bounds write issue in siman.exe that can run code if a user opens a malicious file.

CVE-2026-8314windowsindustrial-controlremote-code-executionmemory-corruption

Updated Jul 15, 2026

lowEPSS 0.004

CVE-2026-45065 in Symfony Routing

Symfony Routing can accept a route value that should fail validation, which can create an off-site redirect-style URL.

CVE-2026-45065phpweb-applicationinput-validationopen-redirect

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45066 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can bypass allowed link or media host rules because some URLs are parsed differently than expected.

CVE-2026-45066phpweb-applicationinput-validationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-47969 in Adobe Audition

Adobe Audition has an out-of-bounds read issue that can expose memory if a user opens a malicious file.

CVE-2026-47969windowsinformation-disclosurememory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48309 in Adobe Audition

Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.

CVE-2026-48309windowsremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48365 in Adobe Audition

Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.

CVE-2026-48365windowsremote-code-executionmemory-corruption

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-48368 in Adobe Audition

Adobe Audition has an out-of-bounds write issue that can run code if a user opens a malicious file.

CVE-2026-48368windowsremote-code-executionmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-55054 in Microsoft Excel and Microsoft 365 Apps

Microsoft Excel has an out-of-bounds read issue that can disclose information when a user opens a crafted file.

CVE-2026-55054windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45753 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss JavaScript URLs in some attributes, which can allow cross-site scripting in sanitized HTML.

CVE-2026-45753phpweb-applicationinput-validationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-45755 in Symfony Mailtrap Mailer

Symfony Mailtrap Mailer does not verify the Mailtrap webhook signature, so a remote attacker can send fake webhook events.

CVE-2026-45755phpweb-applicationinput-validationauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-47767 in Symfony Runtime

Symfony Runtime can still let a crafted web request change APP_ENV or APP_DEBUG on affected patched versions, bypassing an earlier fix.

CVE-2026-47767phpweb-applicationinput-validation

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45068 in Symfony Mailer

Symfony Mailer can pass a dash-prefixed recipient address to SendmailTransport in an unsafe way, which can let an attacker inject sendmail arguments.

CVE-2026-45068phpweb-applicationremote-code-executioninput-validation

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-9341 in Academy LMS

Academy LMS lets a logged-in subscriber change a user id value and read, change, or delete another user's private lesson notes.

CVE-2026-9341wordpressauthorization-bypassidor

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-61952 in Bulk Edit Products for WooCommerce - WP Sheet Editor

Bulk Edit Products for WooCommerce - WP Sheet Editor misses an authorization check, so an author-level user can run an action they should not be allowed to run.

CVE-2026-61952wordpresswoocommerceauthorization-bypass

Updated Jul 15, 2026

infoEPSS 0.001

CVE-2026-58034 in MediaWiki CheckUser

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue. This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.

CVE-2026-58034phpweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.001

CVE-2026-58035 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue.

CVE-2026-58035phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5135 in Red Hat Satellite

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.

CVE-2026-5135linuxdevopsweb-applicationauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-5138 in Red Hat Satellite

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.

CVE-2026-5138linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-5142 in Red Hat Satellite

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

CVE-2026-5142linuxnetwork-securitydevopsweb-application

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-6682 in FatFs

In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlled file-size metadata and unsafe read lengths in downstream callers. This maps to CWE-190 (Integer Overflow or Wraparound). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). Remote delivery is also possible in OTA/update pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.

CVE-2026-6682supply-chainremote-code-executioninput-validationmemory-corruption

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6683 in FatFs

FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to be zero during write/sync operations. This maps to CWE-369 (Divide By Zero). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). Network-delivered update media can make this remote in some pipelines. The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6683supply-chaindenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6684 in FatFs

FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived from GPT header field GPTH_PtNum, enabling extremely long or effectively infinite mount-time scans. This maps to CWE-835 (Loop with Unreachable Exit Condition). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6684supply-chaindenial-of-service

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6685 in FatFs

FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read() / f_write() (fp->sect - sect < cc) during interleaved read/write on fragmented filesystems. This maps to CWE-191 (Integer Underflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H (6.1, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.

CVE-2026-6685supply-chaininput-validation

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-6686 in FatFs

FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-filling newly allocated clusters. This maps to CWE-908 (Use of Uninitialized Resource). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (4.6, Medium). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Partial.

CVE-2026-6686supply-chaininformation-disclosure

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-6687 in FatFs

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec maximums. This maps to CWE-121 (Stack-based Buffer Overflow). Estimated CVSS v3.1 vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (7.6, High). The estimated CISA SSVC vectors are Exploitation: PoC, Technical Impact: Total.

CVE-2026-6687supply-chainmemory-corruption

Updated Jul 15, 2026