CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-65313
8.1 HIGH

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to …

Jul 31, 2026
CVE-2026-65310
7.5 HIGH

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on …

Jul 31, 2026
CVE-2026-65309
7.5 HIGH

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows …

Jul 31, 2026
CVE-2026-16236
8.8 HIGH

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing …

Jul 31, 2026
CVE-2026-15258
8.1 HIGH

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a …

Jul 31, 2026
CVE-2026-15048
7.5 HIGH

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history …

Jul 31, 2026
CVE-2026-14930
7.5 HIGH

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users …

Jul 31, 2026
CVE-2026-14830
7.5 HIGH

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order …

Jul 31, 2026
CVE-2026-14333
7.5 HIGH

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing …

Jul 31, 2026
CVE-2026-14319
7.5 HIGH

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve …

Jul 31, 2026
CVE-2026-13609
8.8 HIGH

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags …

Jul 31, 2026
CVE-2026-13392
7.2 HIGH

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim …

Jul 31, 2026
CVE-2026-12721
8.6 HIGH

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, …

Jul 31, 2026
CVE-2026-12720
7.5 HIGH

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to …

Jul 31, 2026
CVE-2026-12695
8.1 HIGH

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an …

Jul 31, 2026
CVE-2026-12251
8.1 HIGH

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration …

Jul 31, 2026
CVE-2026-63222
7.5 HIGH

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote …

Jul 31, 2026
CVE-2026-56673
7.5 HIGH

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to …

Jul 31, 2026
CVE-2026-56672
8.2 HIGH

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, …

Jul 31, 2026
CVE-2026-56671
7.5 HIGH

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route …

Jul 31, 2026
CVE-2026-56670
8.2 HIGH

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline …

Jul 31, 2026
CVE-2026-55502
7.1 HIGH

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and …

Jul 31, 2026
CVE-2026-43832
7.5 HIGH

Full details and mitigation steps are currently restricted and will be published at a later date.

Jul 31, 2026
CVE-2026-43831
7.5 HIGH

Full details and mitigation steps are currently restricted and will be published at a later date.

Jul 31, 2026
CVE-2026-43829
7.5 HIGH

Full details and mitigation steps are currently restricted and will be published at a later date.

Jul 31, 2026
CVE-2026-18157
7.8 HIGH

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. …

Jul 31, 2026
CVE-2026-66420
8.8 HIGH

MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early …

Jul 30, 2026
CVE-2026-66360
7.5 HIGH

The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of …

Jul 30, 2026
CVE-2026-65423
8.8 HIGH

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

Jul 30, 2026
CVE-2026-63035
8.1 HIGH

A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary …

Jul 30, 2026
CVE-2026-63559
7.5 HIGH

An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.

Jul 30, 2026
CVE-2026-62246
8.5 HIGH

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from …

Jul 30, 2026
CVE-2026-18064
7.5 HIGH

An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in …

Jul 30, 2026
CVE-2026-12562
8.8 HIGH

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. …

Jul 30, 2026
CVE-2026-68500
7.5 HIGH

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled …

Jul 30, 2026
CVE-2026-67527
7.6 HIGH

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve …

Jul 30, 2026
CVE-2026-67207
8.8 HIGH

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP …

Jul 30, 2026
CVE-2026-67206
8.8 HIGH

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file …

Jul 30, 2026
CVE-2026-11536
8.5 HIGH

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

Jul 30, 2026
CVE-2026-66416
8.8 HIGH

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel …

Jul 30, 2026
CVE-2026-66415
8.5 HIGH

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames …

Jul 30, 2026
CVE-2026-61536
7.5 HIGH

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of …

Jul 30, 2026
CVE-2026-18140
7.5 HIGH

Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, …

Jul 30, 2026
CVE-2026-15978
7.5 HIGH

SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to …

Jul 30, 2026
CVE-2026-15977
7.5 HIGH

SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

Jul 30, 2026
CVE-2026-13444
8.1 HIGH

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma …

Jul 30, 2026
CVE-2026-12942
7.5 HIGH

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL …

Jul 30, 2026
CVE-2026-12733
7.5 HIGH

IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

Jul 30, 2026
CVE-2026-10545
7.5 HIGH

IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect users to arbitrary external websites via …

Jul 30, 2026
CVE-2026-10535
8.4 HIGH

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.

Jul 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.