CVE catalog
Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.
394,950 CVEs · 1,717 known exploited · 2,982 Windows CVEs with a fix we can name
Newest first.
| CVE | Severity | CVSS | Exploited | Fix | Published | Description |
|---|---|---|---|---|---|---|
| CVE-2026-82760 | - | - | - | - | 2026-09-17 | Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in lib/ash_authentication/base.ex splits its argument into one binary per character a... |
| CVE-2026-82759 | - | - | - | - | 2026-09-17 | Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. AshAuthentication.AddOn.AuditLog.IpPrivacy.hash_ip/1 computes a single unkeyed :cry... |
| CVE-2026-82723 | - | - | - | - | 2026-09-17 | Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthentication.AddOn.AuditLog.Auditor.build_extra_data/4, which takes :actor from the acti... |
| CVE-2026-82685 | - | - | - | - | 2026-09-17 | Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token issued to one user is accepted on any other user's record. AshAuthentication.AddOn... |
| CVE-2026-81829 | Medium | 5.3 | - | - | 2026-09-17 | A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inboun... |
| CVE-2026-81637 | - | - | - | - | 2026-09-17 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthentication.Strategy.OAuth2.Plug.callback/2 clears the stored session_params through a rebi... |
| CVE-2026-81632 | - | - | - | - | 2026-09-17 | Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password sign-in, AshAuthentication.Phoenix.Components.Pa... |
| CVE-2026-81453 | Medium | 6.5 | - | - | 2026-09-17 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
| CVE-2026-81443 | Medium | 6.4 | - | - | 2026-09-17 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
| CVE-2026-81442 | High | 8.1 | - | - | 2026-09-17 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. |
| CVE-2026-80355 | Medium | 5.4 | - | - | 2026-09-17 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
| CVE-2026-80218 | - | - | - | - | 2026-09-17 | Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_keys_from_subject/2 parses the JWT sub clai... |
| CVE-2026-78528 | Medium | 5.3 | - | - | 2026-09-17 | Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. |
| CVE-2026-78295 | High | 8.8 | - | - | 2026-09-17 | Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions. |
| CVE-2026-78294 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. |
| CVE-2026-78223 | - | - | - | - | 2026-09-17 | Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it... |
| CVE-2026-74017 | Medium | 5.3 | - | - | 2026-09-17 | Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. |
| CVE-2026-74005 | Medium | 5.4 | - | - | 2026-09-17 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. |
| CVE-2026-74002 | Medium | 5.3 | - | - | 2026-09-17 | Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. |
| CVE-2026-74000 | Medium | 5.3 | - | - | 2026-09-17 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. |
| CVE-2026-73999 | Medium | 5.4 | - | - | 2026-09-17 | Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. |
| CVE-2026-71568 | Medium | 5.3 | - | - | 2026-09-17 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity. |
| CVE-2026-66676 | Medium | 5.3 | - | - | 2026-09-17 | Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. |
| CVE-2026-66631 | High | 7.6 | - | - | 2026-09-17 | Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions. |
| CVE-2026-66630 | High | 7.6 | - | - | 2026-09-17 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. |
| CVE-2026-66628 | High | 7.6 | - | - | 2026-09-17 | Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions. |
| CVE-2026-66626 | High | 7.6 | - | - | 2026-09-17 | Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions. |
| CVE-2026-66625 | High | 7.6 | - | - | 2026-09-17 | Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions. |
| CVE-2026-66624 | High | 7.6 | - | - | 2026-09-17 | Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions. |
| CVE-2026-66619 | High | 7.6 | - | - | 2026-09-17 | Administrator SQL Injection in Newsletters <= 4.18 versions. |
| CVE-2026-66618 | High | 7.6 | - | - | 2026-09-17 | Administrator SQL Injection in WP Maps <= 4.9.9 versions. |
| CVE-2026-66617 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. |
| CVE-2026-66608 | Medium | 6.4 | - | - | 2026-09-17 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. |
| CVE-2026-66580 | High | 8.5 | - | - | 2026-09-17 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. |
| CVE-2026-66579 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. |
| CVE-2026-66578 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. |
| CVE-2026-66577 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. |
| CVE-2026-66576 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. |
| CVE-2026-66575 | Medium | 5.3 | - | - | 2026-09-17 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. |
| CVE-2026-66574 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. |
| CVE-2026-66573 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. |
| CVE-2026-66572 | Medium | 6.5 | - | - | 2026-09-17 | Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. |
| CVE-2026-66571 | High | 7.1 | - | - | 2026-09-17 | Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions. |
| CVE-2026-62108 | Critical | 9.8 | - | - | 2026-09-17 | Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions. |
| CVE-2026-62104 | Critical | 10 | - | - | 2026-09-17 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. |
| CVE-2026-62101 | Critical | 9.8 | - | - | 2026-09-17 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. |
| CVE-2026-14850 | - | - | - | - | 2026-09-17 | The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership. |
| CVE-2026-92932 | - | - | - | - | 2026-09-17 | In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] && strpos($input, 'http://') === 0 || strpos($input, 'https://') === 0. Because PHP'... |
| CVE-2026-92921 | Medium | 4.9 | - | - | 2026-09-17 | admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligible computational effort. |
| CVE-2026-92920 | Medium | 5.4 | - | - | 2026-09-17 | admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user... |
What the Fix column means
A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.
If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.
Where the data comes from
CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.