CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76216
7.5 HIGH

Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with users.id == N at three …

Aug 19, 2026
CVE-2026-76214
7.4 HIGH

phpMyFAQ before 4.1.7 fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAuthn controller saves the mutated key objects back to the …

Aug 19, 2026
CVE-2026-76213
7.4 HIGH

phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and reset on each successful password re-authentication. …

Aug 19, 2026
CVE-2026-76208
8.2 HIGH

phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, after a successful LDAP bind the code calls …

Aug 19, 2026
CVE-2026-76207
8.1 HIGH

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a …

Aug 19, 2026
CVE-2026-76205
8.1 HIGH

phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string before embedding it in …

Aug 19, 2026
CVE-2026-75918
8.8 HIGH

phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers can read the tracking file …

Aug 19, 2026
CVE-2026-75917
8.6 HIGH

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document …

Aug 19, 2026
CVE-2026-75916
8.6 HIGH

SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src/protyle/hint/extend.ts), a candidate block's name, alias, and memo …

Aug 19, 2026
CVE-2026-71694
8.8 HIGH

An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return …

Aug 19, 2026
CVE-2026-70422
8.1 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged …

Aug 19, 2026
CVE-2026-70421
7.2 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, …

Aug 19, 2026
CVE-2026-56088
7.1 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged …

Aug 19, 2026
CVE-2026-54796
7.2 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high …

Aug 19, 2026
CVE-2026-54795
8.8 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 19, 2026
CVE-2026-54794
7.2 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, …

Aug 19, 2026
CVE-2026-51367
7.5 HIGH

An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter

Aug 19, 2026
CVE-2026-43961
7.8 HIGH

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during …

Aug 19, 2026
CVE-2024-58376
8.8 HIGH

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary …

Aug 19, 2026
CVE-2020-37267
7.5 HIGH

Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION …

Aug 19, 2026
CVE-2019-25766
7.5 HIGH

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is …

Aug 19, 2026
CVE-2026-76235
7.5 HIGH

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, …

Aug 19, 2026
CVE-2026-73394
7.5 HIGH

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.

Aug 19, 2026
CVE-2026-73387
8.1 HIGH

Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

Aug 19, 2026
CVE-2026-73386
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.

Aug 19, 2026
CVE-2026-73385
7.5 HIGH

Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.

Aug 19, 2026
CVE-2026-73384
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

Aug 19, 2026
CVE-2026-73354
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.

Aug 19, 2026
CVE-2026-73184
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.

Aug 19, 2026
CVE-2026-73182
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.

Aug 19, 2026
CVE-2026-66668
8.5 HIGH

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

Aug 19, 2026
CVE-2026-66596
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.

Aug 19, 2026
CVE-2026-61986
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.

Aug 19, 2026
CVE-2026-32552
8.5 HIGH

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

Aug 19, 2026
CVE-2026-58088
7.4 HIGH

The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the …

Aug 19, 2026
CVE-2026-58087
7.8 HIGH

The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer …

Aug 19, 2026
CVE-2026-58083
8.4 HIGH

While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before …

Aug 19, 2026
CVE-2026-75981
7.2 HIGH

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting in versions up to and including …

Aug 19, 2026
CVE-2026-15780
7.2 HIGH

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions …

Aug 19, 2026
CVE-2026-18973
7.3 HIGH

A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component …

Aug 6, 2026
CVE-2026-67869
7.5 HIGH

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments …

Aug 6, 2026
CVE-2026-18970
7.3 HIGH

A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the …

Aug 6, 2026
CVE-2026-18969
7.3 HIGH

A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing …

Aug 6, 2026
CVE-2026-67863
7.5 HIGH

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after …

Aug 5, 2026
CVE-2026-71321
7.5 HIGH

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled …

Aug 5, 2026
CVE-2026-71320
8.1 HIGH

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props …

Aug 5, 2026
CVE-2026-71316
7.5 HIGH

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can be returned before route middleware and …

Aug 5, 2026
CVE-2026-71315
8.2 HIGH

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when …

Aug 5, 2026
CVE-2026-71314
7.5 HIGH

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island v-for prop, …

Aug 5, 2026
CVE-2026-71312
8.0 HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates remote SFTP paths …

Aug 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.