CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-66611
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.

Aug 20, 2026
CVE-2026-66607
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.

Aug 20, 2026
CVE-2026-66606
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.

Aug 20, 2026
CVE-2026-66605
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.

Aug 20, 2026
CVE-2026-66604
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.

Aug 20, 2026
CVE-2026-66598
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

Aug 20, 2026
CVE-2026-66597
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.

Aug 20, 2026
CVE-2026-66594
8.5 HIGH

Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

Aug 20, 2026
CVE-2026-66590
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.

Aug 20, 2026
CVE-2026-66582
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

Aug 20, 2026
CVE-2026-66581
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.

Aug 20, 2026
CVE-2026-28150
8.1 HIGH

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

Aug 20, 2026
CVE-2025-15637
8.1 HIGH

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

Aug 20, 2026
CVE-2026-73198
7.5 HIGH

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. …

Aug 20, 2026
CVE-2026-73197
7.5 HIGH

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This …

Aug 20, 2026
CVE-2026-18917
7.8 HIGH

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted …

Aug 20, 2026
CVE-2026-14952
7.5 HIGH

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, …

Aug 20, 2026
CVE-2026-14951
8.0 HIGH

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

Aug 20, 2026
CVE-2026-14948
8.8 HIGH

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for …

Aug 20, 2026
CVE-2026-14947
7.2 HIGH

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files …

Aug 20, 2026
CVE-2026-14946
7.2 HIGH

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper …

Aug 20, 2026
CVE-2026-75963
7.5 HIGH

The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. …

Aug 20, 2026
CVE-2026-15049
7.2 HIGH

The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and …

Aug 20, 2026
CVE-2026-76795
7.3 HIGH

A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. The …

Aug 20, 2026
CVE-2026-76783
7.3 HIGH

A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads …

Aug 20, 2026
CVE-2026-76764
7.3 HIGH

A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component …

Aug 20, 2026
CVE-2026-76762
7.3 HIGH

A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument …

Aug 20, 2026
CVE-2026-76928
7.5 HIGH

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76886
8.1 HIGH

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76880
7.5 HIGH

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76879
7.5 HIGH

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76761
7.3 HIGH

A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the component Management API. Such …

Aug 19, 2026
CVE-2026-76760
7.3 HIGH

A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of …

Aug 19, 2026
CVE-2026-76832
8.8 HIGH

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in …

Aug 19, 2026
CVE-2026-76591
7.4 HIGH

A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. …

Aug 19, 2026
CVE-2026-76403
7.4 HIGH

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from …

Aug 19, 2026
CVE-2026-76402
8.2 HIGH

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a …

Aug 19, 2026
CVE-2026-76399
8.1 HIGH

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing …

Aug 19, 2026
CVE-2026-76397
8.1 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, …

Aug 19, 2026
CVE-2026-76396
7.5 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and …

Aug 19, 2026
CVE-2026-76395
8.8 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading …

Aug 19, 2026
CVE-2026-76394
8.3 HIGH

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure …

Aug 19, 2026
CVE-2026-76391
8.3 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, …

Aug 19, 2026
CVE-2026-76389
8.8 HIGH

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted …

Aug 19, 2026
CVE-2026-76388
8.1 HIGH

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) …

Aug 19, 2026
CVE-2026-76387
8.1 HIGH

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing …

Aug 19, 2026
CVE-2026-76362
7.4 HIGH

In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State …

Aug 19, 2026
CVE-2026-76357
7.6 HIGH

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) …

Aug 19, 2026
CVE-2026-76356
8.1 HIGH

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint …

Aug 19, 2026
CVE-2026-76355
7.5 HIGH

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer …

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.