CVE Database

9856+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-51541
9.1 CRITICAL

OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker …

Jul 13, 2026
CVE-2026-51540
9.8 CRITICAL

OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of …

Jul 13, 2026
CVE-2026-51538
9.1 CRITICAL

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, …

Jul 13, 2026
CVE-2026-51537
9.1 CRITICAL

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can …

Jul 13, 2026
CVE-2026-51536
9.1 CRITICAL

In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, …

Jul 13, 2026
CVE-2026-58409
9.1 CRITICAL

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing …

Jul 13, 2026
CVE-2026-61500
9.8 CRITICAL

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients …

Jul 13, 2026
CVE-2026-57433
9.8 CRITICAL

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from …

Jul 13, 2026
CVE-2026-13221
9.1 CRITICAL

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie …

Jul 13, 2026
CVE-2026-61498
9.8 CRITICAL

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying …

Jul 13, 2026
CVE-2026-60121
9.8 CRITICAL

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a …

Jul 13, 2026
CVE-2026-40469
9.1 CRITICAL

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and …

Jul 13, 2026
CVE-2026-40468
9.1 CRITICAL

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and …

Jul 13, 2026
CVE-2026-59518
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

Jul 13, 2026
CVE-2026-59515
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from …

Jul 13, 2026
CVE-2026-57813
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.

Jul 13, 2026
CVE-2026-57811
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX …

Jul 13, 2026
CVE-2026-57770
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

Jul 13, 2026
CVE-2026-57744
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= …

Jul 13, 2026
CVE-2026-57739
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This …

Jul 13, 2026
CVE-2026-57738
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

Jul 13, 2026
CVE-2026-57726
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from …

Jul 13, 2026
CVE-2026-57724
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

Jul 13, 2026
CVE-2026-57719
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= …

Jul 13, 2026
CVE-2026-57714
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from …

Jul 13, 2026
CVE-2026-57710
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a …

Jul 13, 2026
CVE-2026-57707
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects …

Jul 13, 2026
CVE-2026-57702
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects …

Jul 13, 2026
CVE-2026-57401
9.9 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a …

Jul 13, 2026
CVE-2026-41041
9.1 CRITICAL

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade …

Jul 13, 2026
CVE-2026-14453
9.6 CRITICAL

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without …

Jul 13, 2026
CVE-2026-57830
9.1 CRITICAL

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Jul 13, 2026
CVE-2026-4769
9.8 CRITICAL

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented …

Jul 13, 2026
CVE-2026-11964
9.1 CRITICAL

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated …

Jul 13, 2026
CVE-2026-15511
9.8 CRITICAL

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the …

Jul 12, 2026
CVE-2026-56271
9.8 CRITICAL

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in …

Jul 12, 2026
CVE-2026-56260
9.1 CRITICAL

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths …

Jul 12, 2026
CVE-2026-61447
10.0 CRITICAL

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers …

Jul 11, 2026
CVE-2026-61445
9.9 CRITICAL

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM …

Jul 11, 2026
CVE-2026-60090
9.8 CRITICAL

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are …

Jul 11, 2026
CVE-2026-57827
9.8 CRITICAL

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jul 11, 2026
CVE-2026-20744
9.8 CRITICAL

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

Jul 10, 2026
CVE-2026-15089
9.1 CRITICAL

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

Jul 10, 2026
CVE-2026-14480
9.9 CRITICAL

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly …

Jul 10, 2026
CVE-2026-11913
9.8 CRITICAL

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

Jul 10, 2026
CVE-2026-12535
9.8 CRITICAL

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

Jul 10, 2026
CVE-2026-10768
9.8 CRITICAL

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

Jul 10, 2026
CVE-2026-9726
9.8 CRITICAL

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 …

Jul 10, 2026
CVE-2026-57807
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password …

Jul 10, 2026
CVE-2026-55879
9.3 CRITICAL

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any …

Jul 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.