CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-85085
9.6 CRITICAL

The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded …

Sep 4, 2026
CVE-2026-80181
9.1 CRITICAL

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, …

Sep 4, 2026
CVE-2026-70403
9.8 CRITICAL

XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

Sep 4, 2026
CVE-2026-69657
9.8 CRITICAL

XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

Sep 4, 2026
CVE-2026-62928
9.8 CRITICAL

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

Sep 4, 2026
CVE-2026-15354
9.8 CRITICAL

The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization …

Sep 4, 2026
CVE-2026-84699
9.1 CRITICAL

Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and …

Sep 2, 2026
CVE-2026-84480
9.8 CRITICAL

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain …

Sep 1, 2026
CVE-2026-84479
9.1 CRITICAL

WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a …

Sep 1, 2026
CVE-2026-84372
9.8 CRITICAL

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication …

Sep 1, 2026
CVE-2026-75604
9.0 CRITICAL

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without …

Sep 1, 2026
CVE-2023-54391
9.8 CRITICAL

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing …

Sep 1, 2026
CVE-2026-73749
9.8 CRITICAL

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities …

Sep 1, 2026
CVE-2026-76658
10.0 CRITICAL

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access …

Sep 1, 2026
CVE-2026-76657
10.0 CRITICAL

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. …

Sep 1, 2026
CVE-2026-73701
9.0 CRITICAL

An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside …

Sep 1, 2026
CVE-2026-73700
9.0 CRITICAL

A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site …

Sep 1, 2026
CVE-2026-19766
9.6 CRITICAL

An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute …

Sep 1, 2026
CVE-2026-79687
9.0 CRITICAL

Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem …

Sep 1, 2026
CVE-2026-18931
9.1 CRITICAL

Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Retrieve Embedded Sensitive Data. This issue affects …

Sep 1, 2026
CVE-2026-78012
9.8 CRITICAL

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without …

Sep 1, 2026
CVE-2026-18808
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO …

Sep 1, 2026
CVE-2026-18210
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company …

Sep 1, 2026
CVE-2026-84121
9.6 CRITICAL

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR …

Sep 1, 2026
CVE-2026-84119
9.6 CRITICAL

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR …

Sep 1, 2026
CVE-2026-51743
9.1 CRITICAL

Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT …

Sep 1, 2026
CVE-2026-18765
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects …

Sep 1, 2026
CVE-2026-84200
9.0 CRITICAL

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive …

Sep 1, 2026
CVE-2026-18550
9.8 CRITICAL

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. …

Sep 1, 2026
CVE-2026-83772
9.9 CRITICAL

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of …

Sep 1, 2026
CVE-2026-75865
9.8 CRITICAL

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file …

Sep 1, 2026
CVE-2026-83524
9.9 CRITICAL

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the …

Aug 31, 2026
CVE-2026-82971
10.0 CRITICAL

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of …

Aug 31, 2026
CVE-2026-82954
9.9 CRITICAL

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation …

Aug 31, 2026
CVE-2026-82226
9.8 CRITICAL

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

Aug 31, 2026
CVE-2026-81780
10.0 CRITICAL

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

Aug 31, 2026
CVE-2026-81779
10.0 CRITICAL

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through …

Aug 31, 2026
CVE-2026-81763
9.3 CRITICAL

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

Aug 31, 2026
CVE-2026-81756
9.3 CRITICAL

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

Aug 31, 2026
CVE-2026-81293
9.3 CRITICAL

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

Aug 31, 2026
CVE-2026-79408
9.8 CRITICAL

An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

Aug 31, 2026
CVE-2026-38577
9.8 CRITICAL

Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.

Aug 31, 2026
CVE-2026-51740
9.8 CRITICAL

Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to …

Aug 31, 2026
CVE-2026-51736
9.1 CRITICAL

Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to …

Aug 31, 2026
CVE-2026-51734
9.8 CRITICAL

Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST …

Aug 31, 2026
CVE-2026-51731
9.1 CRITICAL

Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to …

Aug 31, 2026
CVE-2026-53552
9.6 CRITICAL

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row …

Aug 31, 2026
CVE-2026-79748
9.9 CRITICAL

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, …

Aug 31, 2026
CVE-2026-51730
9.1 CRITICAL

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request …

Aug 31, 2026
CVE-2026-51729
9.1 CRITICAL

Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.