More free tools →

CVE catalog

Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.

394,950 CVEs · 1,717 known exploited · 2,982 Windows CVEs with a fix we can name

Newest first.

CVE Severity CVSS Exploited Fix Published Description
CVE-2026-82760 - - - - 2026-09-17 Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in lib/ash_authentication/base.ex splits its argument into one binary per character a...
CVE-2026-82759 - - - - 2026-09-17 Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. AshAuthentication.AddOn.AuditLog.IpPrivacy.hash_ip/1 computes a single unkeyed :cry...
CVE-2026-82723 - - - - 2026-09-17 Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthentication.AddOn.AuditLog.Auditor.build_extra_data/4, which takes :actor from the acti...
CVE-2026-82685 - - - - 2026-09-17 Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token issued to one user is accepted on any other user's record. AshAuthentication.AddOn...
CVE-2026-81829 Medium 5.3 - - 2026-09-17 A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an inboun...
CVE-2026-81637 - - - - 2026-09-17 Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthentication.Strategy.OAuth2.Plug.callback/2 clears the stored session_params through a rebi...
CVE-2026-81632 - - - - 2026-09-17 Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its owner. After a successful password sign-in, AshAuthentication.Phoenix.Components.Pa...
CVE-2026-81453 Medium 6.5 - - 2026-09-17 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
CVE-2026-81443 Medium 6.4 - - 2026-09-17 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
CVE-2026-81442 High 8.1 - - 2026-09-17 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.
CVE-2026-80355 Medium 5.4 - - 2026-09-17 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
CVE-2026-80218 - - - - 2026-09-17 Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.SignInWithTokenPreparation.extract_primary_keys_from_subject/2 parses the JWT sub clai...
CVE-2026-78528 Medium 5.3 - - 2026-09-17 Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
CVE-2026-78295 High 8.8 - - 2026-09-17 Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
CVE-2026-78294 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-78223 - - - - 2026-09-17 Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthentication.TokenResource.RevokeTokenChange.change/3 reads the :token argument and decodes it...
CVE-2026-74017 Medium 5.3 - - 2026-09-17 Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
CVE-2026-74005 Medium 5.4 - - 2026-09-17 Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
CVE-2026-74002 Medium 5.3 - - 2026-09-17 Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
CVE-2026-74000 Medium 5.3 - - 2026-09-17 Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
CVE-2026-73999 Medium 5.4 - - 2026-09-17 Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
CVE-2026-71568 Medium 5.3 - - 2026-09-17 In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
CVE-2026-66676 Medium 5.3 - - 2026-09-17 Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
CVE-2026-66631 High 7.6 - - 2026-09-17 Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
CVE-2026-66630 High 7.6 - - 2026-09-17 Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
CVE-2026-66628 High 7.6 - - 2026-09-17 Shop manager SQL Injection in WP-Lister Lite for eBay <= 3.8.11 versions.
CVE-2026-66626 High 7.6 - - 2026-09-17 Editor SQL Injection in SKT Addons for Elementor <= 4.0 versions.
CVE-2026-66625 High 7.6 - - 2026-09-17 Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
CVE-2026-66624 High 7.6 - - 2026-09-17 Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
CVE-2026-66619 High 7.6 - - 2026-09-17 Administrator SQL Injection in Newsletters <= 4.18 versions.
CVE-2026-66618 High 7.6 - - 2026-09-17 Administrator SQL Injection in WP Maps <= 4.9.9 versions.
CVE-2026-66617 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions.
CVE-2026-66608 Medium 6.4 - - 2026-09-17 Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions.
CVE-2026-66580 High 8.5 - - 2026-09-17 Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
CVE-2026-66579 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions.
CVE-2026-66578 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
CVE-2026-66577 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions.
CVE-2026-66576 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions.
CVE-2026-66575 Medium 5.3 - - 2026-09-17 Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.
CVE-2026-66574 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.
CVE-2026-66573 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.
CVE-2026-66572 Medium 6.5 - - 2026-09-17 Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.
CVE-2026-66571 High 7.1 - - 2026-09-17 Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.
CVE-2026-62108 Critical 9.8 - - 2026-09-17 Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
CVE-2026-62104 Critical 10 - - 2026-09-17 Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
CVE-2026-62101 Critical 9.8 - - 2026-09-17 Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.
CVE-2026-14850 - - - - 2026-09-17 The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users without proving account ownership.
CVE-2026-92932 - - - - 2026-09-17 In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] && strpos($input, 'http://') === 0 || strpos($input, 'https://') === 0. Because PHP'...
CVE-2026-92921 Medium 4.9 - - 2026-09-17 admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force attacks due to negligible computational effort.
CVE-2026-92920 Medium 5.4 - - 2026-09-17 admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disablement to authenticate requests, as the AuthInterceptor never re-validates the user...

What the Fix column means

A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.

If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.

Where the data comes from

CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.