CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-56842
7.5 HIGH

A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist …

Jul 2, 2026
CVE-2026-56841
8.8 HIGH

A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate …

Jul 2, 2026
CVE-2026-56004
10.0 CRITICAL

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a …

Jul 2, 2026
CVE-2026-55119
8.1 HIGH

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate …

Jul 2, 2026
CVE-2026-55118
8.3 HIGH

A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application …

Jul 2, 2026
CVE-2026-55117
8.6 HIGH

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host …

Jul 2, 2026
CVE-2026-55116
9.0 CRITICAL

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running …

Jul 2, 2026
CVE-2026-55115
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges …

Jul 2, 2026
CVE-2026-55114
8.8 HIGH

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate …

Jul 2, 2026
CVE-2026-55113
7.5 HIGH

A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial …

Jul 2, 2026
CVE-2026-55112
7.5 HIGH

A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi …

Jul 2, 2026
CVE-2026-55111
7.5 HIGH

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the …

Jul 2, 2026
CVE-2026-55110
7.5 HIGH

A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to …

Jul 2, 2026
CVE-2026-54409
7.5 HIGH

A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass …

Jul 2, 2026
CVE-2026-54408
8.6 HIGH

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data …

Jul 2, 2026
CVE-2026-54407
8.6 HIGH

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain …

Jul 2, 2026
CVE-2026-54406
8.7 HIGH

A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application …

Jul 2, 2026
CVE-2026-54405
7.5 HIGH

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of …

Jul 2, 2026
CVE-2026-54404
8.8 HIGH

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to …

Jul 2, 2026
CVE-2026-54403
8.6 HIGH

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of …

Jul 2, 2026
CVE-2026-54402
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a …

Jul 2, 2026
CVE-2026-54401
7.7 HIGH

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS …

Jul 2, 2026
CVE-2026-54400
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate …

Jul 2, 2026
CVE-2026-53358

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() l2cap_chan_close() removes the channel from …

Jul 2, 2026
CVE-2026-53357

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() bt_accept_dequeue() unlinks a not-yet-accepted child from the parent …

Jul 2, 2026
CVE-2026-50748
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Jul 2, 2026
CVE-2026-50747
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application …

Jul 2, 2026
CVE-2026-50746
10.0 CRITICAL

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection …

Jul 2, 2026
CVE-2026-12168
7.8 HIGH

An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in …

Jul 2, 2026
CVE-2026-12167
7.8 HIGH

The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that …

Jul 2, 2026
CVE-2026-12166
5.5 MEDIUM

A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via crafted requests …

Jul 2, 2026
CVE-2026-4767
9.8 CRITICAL

Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.

Jul 2, 2026
CVE-2026-5524
9.8 CRITICAL

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including …

Jul 2, 2026
CVE-2026-58653
4.3 MEDIUM

PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues …

Jul 2, 2026
CVE-2026-58652
7.5 HIGH

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the …

Jul 2, 2026
CVE-2026-4772
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored XSS. This issue affects WAF-ASP: from …

Jul 2, 2026
CVE-2026-4770
4.6 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. Web Application Firewall allows DOM-Based XSS. This issue affects …

Jul 2, 2026
CVE-2026-57766
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

Jul 2, 2026
CVE-2026-57765
8.5 HIGH

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

Jul 2, 2026
CVE-2026-57764
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

Jul 2, 2026
CVE-2026-57763
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

Jul 2, 2026
CVE-2026-57762
5.9 MEDIUM

Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

Jul 2, 2026
CVE-2026-57761
7.1 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

Jul 2, 2026
CVE-2026-57760
5.3 MEDIUM

Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.

Jul 2, 2026
CVE-2026-57759
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

Jul 2, 2026
CVE-2026-57758
7.1 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

Jul 2, 2026
CVE-2026-57757
7.1 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

Jul 2, 2026
CVE-2026-57756
8.5 HIGH

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

Jul 2, 2026
CVE-2026-57755
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

Jul 2, 2026
CVE-2026-57754
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

Jul 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.