Free Security Tools & CVE Database

Track CVE vulnerabilities, run security tools, and stay informed with expert cybersecurity guides.

🛡️ CVE Vulnerability Database (10,106+ CVEs tracked) Browse all →

🔴 Critical (990) 🟠 High (3,268) 🟡 Medium 🟢 Low 📅 2026
CVE-2026-10057 4.8
ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
CVE-2026-10056 7.5
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote attacker to steal the session token of an authenticated user and perform Administrator Account Takeove...
CVE-2026-10052 4.1
A flaw was found in the Quay config-tool's LDAP and SMTP validation functions. An attacker with config editor access can exploit these functions, which make outbound connections to user-supplied endpoints without proper IP or host filtering. This allows the attacker to perform internal network recon...
CVE-2026-10039 4.9
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter in all versions up to, and including, 3.28.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it...
CVE-2026-9243 6.4
The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in versions up to, and including, 6.4.15 This is due to insufficient output escaping in the render() function, where the carousel_dir...
CVE-2026-4776 7.1
An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitization of nested query parameters, an authenticated API user can bypass input filtering and inject arbitrary SQL commands.
🏢 Browse CVEs by Vendor:
Google (210) Linux (187) Microsoft (121) Openclaw (110) Apache (101) Mozilla (81) Axiomthemes (58) Schneider-Electric (55)

🛠️ Security Tools View all →

🔐
Password Checker
Test your password strength
🔑
Password Generator
Generate secure passwords
🛡️
Privacy Score Quiz
Rate your digital privacy habits
🎣
Phishing Detector
Analyze suspicious emails
🔓
Data Breach Info
What to do after a breach
🌐
VPN Comparison
Compare top VPN services
🔒
Encryption Strength
Evaluate algorithm security
📶
WiFi Security
Audit your WiFi settings
📱
2FA Guide
2FA support by service
👁️
Social Privacy Audit
Lock down your social accounts

📝 Latest Articles