CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-88016
7.1 HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, …

Sep 10, 2026
CVE-2026-88015
5.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true …

Sep 10, 2026
CVE-2026-88014
6.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend …

Sep 10, 2026
CVE-2026-88013
3.7 LOW

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches …

Sep 10, 2026
CVE-2026-88012
5.3 MEDIUM

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the …

Sep 10, 2026
CVE-2026-88011
8.1 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as …

Sep 10, 2026
CVE-2026-88009
8.2 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go …

Sep 10, 2026
CVE-2026-87913
5.9 MEDIUM

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source …

Sep 10, 2026
CVE-2026-87912
5.9 MEDIUM

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private …

Sep 10, 2026
CVE-2026-81468
9.1 CRITICAL

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A …

Sep 10, 2026
CVE-2026-81467
9.8 CRITICAL

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An …

Sep 10, 2026
CVE-2026-81052
6.8 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit …

Sep 10, 2026
CVE-2026-81051
6.6 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could …

Sep 10, 2026
CVE-2026-81049
4.4 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit …

Sep 10, 2026
CVE-2026-81048
9.6 CRITICAL

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with …

Sep 10, 2026
CVE-2026-81046
9.4 CRITICAL

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Sep 10, 2026
CVE-2026-79987
8.8 HIGH

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Sep 10, 2026
CVE-2026-4130
7.1 HIGH

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive …

Sep 10, 2026
CVE-2026-4129
8.1 HIGH

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files …

Sep 10, 2026
CVE-2026-88924
7.0 HIGH

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling …

Sep 10, 2026
CVE-2026-88898
6.5 MEDIUM

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into …

Sep 10, 2026
CVE-2026-88897
5.9 MEDIUM

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or …

Sep 10, 2026
CVE-2026-88008
9.1 CRITICAL

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, …

Sep 10, 2026
CVE-2026-88007
9.1 CRITICAL

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, …

Sep 10, 2026
CVE-2026-88006
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for …

Sep 10, 2026
CVE-2026-88005
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for …

Sep 10, 2026
CVE-2026-88004
7.4 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but …

Sep 10, 2026
CVE-2026-85310
6.5 MEDIUM

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

Sep 10, 2026
CVE-2026-84821
7.5 HIGH

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

Sep 10, 2026
CVE-2026-84819
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.

Sep 10, 2026
CVE-2026-84816
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.

Sep 10, 2026
CVE-2026-81805
8.1 HIGH

Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

Sep 10, 2026
CVE-2026-81804
7.5 HIGH

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

Sep 10, 2026
CVE-2026-81803
7.5 HIGH

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

Sep 10, 2026
CVE-2026-81801
8.1 HIGH

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

Sep 10, 2026
CVE-2026-81800
9.3 CRITICAL

Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

Sep 10, 2026
CVE-2026-81799
7.5 HIGH

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

Sep 10, 2026
CVE-2026-81796
7.3 HIGH

Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.

Sep 10, 2026
CVE-2026-81795
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.

Sep 10, 2026
CVE-2026-81794
7.5 HIGH

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

Sep 10, 2026
CVE-2026-81793
6.5 MEDIUM

Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.

Sep 10, 2026
CVE-2026-81791
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

Sep 10, 2026
CVE-2026-81789
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This …

Sep 10, 2026
CVE-2026-81788
6.3 MEDIUM

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

Sep 10, 2026
CVE-2026-81787
6.5 MEDIUM

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

Sep 10, 2026
CVE-2026-81786
7.5 HIGH

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.

Sep 10, 2026
CVE-2026-81785
6.5 MEDIUM

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

Sep 10, 2026
CVE-2026-81784
8.1 HIGH

Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.

Sep 10, 2026
CVE-2026-81783
7.1 HIGH

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

Sep 10, 2026
CVE-2026-81782
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.