CVE catalog
Published CVEs with severity, CVSS and CISA KEV status. For Windows we also carry the part most catalogs leave blank: the update that fixes it, and the build revision that carries the fix.
394,950 CVEs · 1,717 known exploited · 2,982 Windows CVEs with a fix we can name
Newest first.
| CVE | Severity | CVSS | Exploited | Fix | Published | Description |
|---|---|---|---|---|---|---|
| CVE-2026-91019 | Medium | 4.9 | - | - | 2026-09-17 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys. |
| CVE-2026-91016 | Medium | 5.3 | - | - | 2026-09-17 | The Motors WordPress plugin before 1.4.121 does not verify that a request is authorized to view a user's non-published listings before returning them, allowing unauthenticated attackers to read any author's draft, pending and private car listings - including titles, prices, media URLs and seller notes - by supplying o... |
| CVE-2026-91015 | Medium | 5.3 | - | - | 2026-09-17 | The Master Addons for Elementor WordPress plugin before 3.1.9 does not perform an authorization check on the AJAX action that deactivates its Popup Builder popups, relying only on a nonce that is publicly output to every visitor, allowing unauthenticated attackers to permanently disable any popup on the site. |
| CVE-2026-91014 | High | 7.1 | - | - | 2026-09-17 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its parameters before reflecting them back in the page, allowing unauthenticated attackers to run arbitrary web scripts in a visitor's browser if they can trick the visitor into following a crafted link... |
| CVE-2026-91011 | Medium | 6.8 | - | - | 2026-09-17 | The EWWW Image Optimizer WordPress plugin before 8.7.7 does not properly escape image attribute values when it rewrites page output, allowing authenticated users with author-level access and above to inject arbitrary JavaScript that is stored in published content and executes in the browser of any user who later views... |
| CVE-2026-91010 | Medium | 4.3 | - | - | 2026-09-17 | The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms WordPress plugin before 5.1.1 does not check the user's capabilities in its message deletion AJAX action, and only tests that a nonce parameter is present rather than validating it, allowing any authenticated user, such as a subscriber, to permanen... |
| CVE-2026-91009 | Medium | 4.3 | - | - | 2026-09-17 | The Active Woot Products Tables for WooCommerce. 100% FREE WordPress plugin before 2.1.3 does not have authorisation and CSRF checks in some of its AJAX actions, allowing any authenticated users, such as subscriber, to change the title of arbitrary posts, pages and products. |
| CVE-2026-91008 | Low | 3.7 | - | - | 2026-09-17 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom regis... |
| CVE-2026-90923 | Medium | 6.5 | - | - | 2026-09-17 | The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders. |
| CVE-2026-90922 | Medium | 5.3 | - | - | 2026-09-17 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. |
| CVE-2026-88904 | High | 8.8 | - | - | 2026-09-17 | The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileg... |
| CVE-2026-88795 | Critical | 9 | - | - | 2026-09-17 | The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers to predict the token and use the access i... |
| CVE-2026-88792 | High | 8.8 | - | - | 2026-09-17 | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry. |
| CVE-2026-87836 | Low | 2.7 | - | - | 2026-09-17 | The Comments Import & Export WordPress plugin before 2.5.4 does not restrict its comment export to users able to moderate comments, nor scope the export to content owned by the requesting user, allowing users with the Author role and above to retrieve every comment on the site, including commenter email addresses, IP a... |
| CVE-2026-87786 | High | 8.8 | - | - | 2026-09-17 | The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputting them inside an inline script, allowing unauthenticated users to store JavaScript that runs in the session of an administrator who later opens the order. |
| CVE-2026-86824 | Medium | 4.8 | - | - | 2026-09-17 | The Newsletter WordPress plugin before 9.3.8 does not generate its email tracking signing key with sufficient entropy and signs its tracking links with an unkeyed hash, allowing an unauthenticated attacker who recovers that key offline to forge tracking links, obtain any subscriber's session token, and read and modify... |
| CVE-2026-86788 | Medium | 6.8 | - | - | 2026-09-17 | The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the... |
| CVE-2026-86710 | Critical | 9.8 | - | - | 2026-09-17 | The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators. |
| CVE-2026-86709 | Critical | 9.8 | - | - | 2026-09-17 | The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators. |
| CVE-2026-86707 | Critical | 9.8 | - | - | 2026-09-17 | The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators. |
| CVE-2026-86446 | Low | 3.7 | - | - | 2026-09-17 | The LearnPress WordPress plugin before 4.4.7 does not restrict the correctness flags it returns when a quiz answer is checked, allowing unauthenticated attackers to obtain the correct answer to every option of a question, along with the instructor's explanation, on courses configured to be taken without enrolling. |
| CVE-2026-85130 | High | 8.8 | - | - | 2026-09-17 | The WPLP Cookie Consent WordPress plugin before 4.4.4 does not escape a value submitted through a public endpoint for the JavaScript context it is later output in on an administrative screen, allowing unauthenticated users to run arbitrary JavaScript in the session of an administrator who interacts with the logged ent... |
| CVE-2026-85128 | High | 7.5 | - | - | 2026-09-17 | The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires... |
| CVE-2025-15697 | High | 7.1 | - | - | 2026-09-17 | The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request. |
| CVE-2026-87935 | High | 8.1 | - | - | 2026-09-17 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returni... |
| CVE-2026-87796 | Critical | 9.8 | - | - | 2026-09-17 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitra... |
| CVE-2026-50604 | - | - | - | - | 2026-09-17 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowin... |
| CVE-2026-25294 | High | 7.4 | - | - | 2026-09-17 | Transient DOS while parsing frame during channel usage. |
| CVE-2026-25290 | High | 7.8 | - | - | 2026-09-17 | Memory Corruption when validating large data buffers from external sources using addition to check buffer length. |
| CVE-2026-25284 | High | 7.3 | - | - | 2026-09-17 | Information Disclosure when a pointer is reused after being deallocated. |
| CVE-2026-25283 | High | 8.8 | - | - | 2026-09-17 | Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size. |
| CVE-2026-25282 | High | 7.9 | - | - | 2026-09-17 | Transient DOS when processing unverified data from a neighboring system causes out of bound memory access. |
| CVE-2026-25281 | High | 7.4 | - | - | 2026-09-17 | Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation. |
| CVE-2026-25280 | High | 7.8 | - | - | 2026-09-17 | Memory corruption when processing escape handling flow with insufficient user buffer sizes. |
| CVE-2026-25278 | High | 7.8 | - | - | 2026-09-17 | Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying. |
| CVE-2026-25275 | High | 7.5 | - | - | 2026-09-17 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. |
| CVE-2026-25261 | Medium | 6.7 | - | - | 2026-09-17 | Memory corruption while processing rear sensor IOCTL calls. |
| CVE-2026-24081 | High | 7.4 | - | - | 2026-09-17 | Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled. |
| CVE-2026-24075 | High | 7.8 | - | - | 2026-09-17 | Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions. |
| CVE-2026-24074 | High | 7.8 | - | - | 2026-09-17 | Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations. |
| CVE-2026-24073 | High | 7.8 | - | - | 2026-09-17 | Memory corruption when processing decode statistics due to insufficient validation of offset against structure size. |
| CVE-2025-59607 | High | 7.8 | - | - | 2026-09-17 | Memory Corruption when copying large input data exceeds normal allocation limits. |
| CVE-2026-92839 | Medium | 4.3 | - | - | 2026-09-17 | Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session. |
| CVE-2026-86311 | Medium | 6.4 | - | - | 2026-09-17 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Auth... |
| CVE-2026-50603 | - | - | - | - | 2026-09-17 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected informa... |
| CVE-2026-89064 | Medium | 5.3 | - | - | 2026-09-17 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin_init` hook, which fires unauthenticated on `admin-ajax.php` and `admin-post.php` r... |
| CVE-2026-92838 | High | 7.8 | - | - | 2026-09-17 | A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location. If successfully exploit... |
| CVE-2026-81546 | High | 7.7 | - | - | 2026-09-17 | The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity document that when opened by a user in Affinity could result in arbitrary code execution. |
| CVE-2026-65388 | High | 7.5 | - | - | 2026-09-16 | A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0. |
| CVE-2026-61599 | - | - | - | - | 2026-09-16 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling `__import__(module_path, ...)`. The module is imported — running its top-level code... |
What the Fix column means
A KB means we hold Microsoft's own remediation data for that CVE: the update that fixes it and, where Microsoft publishes one, the build revision that carries the fix. That is the difference between knowing a CVE exists and knowing whether the machine in front of you is still exposed to it.
If you want that answered for a specific machine rather than a specific CVE, paste your build into the patch checker. It walks the supersedence chain, so it can tell you that the update you actually installed covers a fix that shipped in an earlier one.
Where the data comes from
CVE records, CVSS scores and descriptions come from NVD. The exploited flag comes from CISA's KEV catalog. Windows fix data comes from Microsoft's own security update feed. We are not endorsed by or certified by any of them.