CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18284
7.8 HIGH

Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Sony XAV-9500ES …

Aug 20, 2026
CVE-2026-18282
8.0 HIGH

Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES …

Aug 20, 2026
CVE-2026-18281
8.0 HIGH

Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES …

Aug 20, 2026
CVE-2026-18279
8.8 HIGH

Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES …

Aug 20, 2026
CVE-2026-18274
7.2 HIGH

Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall …

Aug 20, 2026
CVE-2026-18270
7.8 HIGH

Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. …

Aug 20, 2026
CVE-2026-18268
7.0 HIGH

Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An …

Aug 20, 2026
CVE-2026-18264
8.8 HIGH

NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required …

Aug 20, 2026
CVE-2026-18263
7.8 HIGH

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of …

Aug 20, 2026
CVE-2026-18262
7.8 HIGH

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of …

Aug 20, 2026
CVE-2026-15686
7.2 HIGH

Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Aug 20, 2026
CVE-2026-15679
7.8 HIGH

Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Aug 20, 2026
CVE-2026-13121
7.8 HIGH

Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of …

Aug 20, 2026
CVE-2026-77004
7.4 HIGH

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn …

Aug 20, 2026
CVE-2026-76998
7.3 HIGH

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. …

Aug 20, 2026
CVE-2026-75140
7.5 HIGH

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by …

Aug 20, 2026
CVE-2026-63043
7.5 HIGH

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users …

Aug 20, 2026
CVE-2026-63042
8.1 HIGH

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data …

Aug 20, 2026
CVE-2026-63040
8.1 HIGH

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. …

Aug 20, 2026
CVE-2026-19611
7.4 HIGH

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A …

Aug 20, 2026
CVE-2026-76996
7.3 HIGH

A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation …

Aug 20, 2026
CVE-2026-63490
7.5 HIGH

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment …

Aug 20, 2026
CVE-2026-61898
7.8 HIGH

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is …

Aug 20, 2026
CVE-2026-61897
7.8 HIGH

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user …

Aug 20, 2026
CVE-2026-49825
8.2 HIGH

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can …

Aug 20, 2026
CVE-2026-16932
8.8 HIGH

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the …

Aug 20, 2026
CVE-2026-16928
7.5 HIGH

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based …

Aug 20, 2026
CVE-2026-16927
7.3 HIGH

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use …

Aug 20, 2026
CVE-2026-16925
7.1 HIGH

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization.

Aug 20, 2026
CVE-2026-16924
7.5 HIGH

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper …

Aug 20, 2026
CVE-2026-16923
7.0 HIGH

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

Aug 20, 2026
CVE-2026-16922
7.0 HIGH

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use …

Aug 20, 2026
CVE-2026-76990
7.3 HIGH

A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation …

Aug 20, 2026
CVE-2026-76833
7.8 HIGH

@cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct …

Aug 20, 2026
CVE-2026-76635
7.2 HIGH

baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL …

Aug 20, 2026
CVE-2026-76633
8.1 HIGH

WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing …

Aug 20, 2026
CVE-2026-76987
7.3 HIGH

A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic …

Aug 20, 2026
CVE-2026-74011
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP …

Aug 20, 2026
CVE-2026-74021
7.5 HIGH

Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.

Aug 20, 2026
CVE-2026-74020
7.5 HIGH

Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.

Aug 20, 2026
CVE-2026-74019
7.1 HIGH

Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.

Aug 20, 2026
CVE-2026-74013
8.5 HIGH

Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

Aug 20, 2026
CVE-2026-73998
8.5 HIGH

Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.

Aug 20, 2026
CVE-2026-68564
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.

Aug 20, 2026
CVE-2026-66677
7.6 HIGH

Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

Aug 20, 2026
CVE-2026-66673
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.

Aug 20, 2026
CVE-2026-66616
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.

Aug 20, 2026
CVE-2026-66615
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.

Aug 20, 2026
CVE-2026-66614
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.

Aug 20, 2026
CVE-2026-66612
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.

Aug 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.