CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-40061
8.7 HIGH

When BIG-IP DNS is provisioned, a vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that may allow an authenticated attacker …

May 13, 2026
CVE-2026-40060
7.5 HIGH

When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. Note: …

May 13, 2026
CVE-2026-39459
7.2 HIGH

A vulnerability exists in iControl REST and the TMOS Shell (tmsh) where a highly privileged, authenticated attacker with at least the Manager role can create …

May 13, 2026
CVE-2026-39458
7.5 HIGH

When a BIG-IP DNS profile enabled with DNS cache is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to …

May 13, 2026
CVE-2026-39455
7.5 HIGH

When the BIG-IP Configuration utility is configured to use Lightweight Directory Access Protocol (LDAP) authentication, undisclosed traffic can cause the httpd process to exhaust the …

May 13, 2026
CVE-2026-36741
7.2 HIGH

U-SPEED AC1200 Gigabit Wi-Fi Router (Model: T18-21K) V1.0 is vulnerable to Command Injection. The Network Time Protocol (NTP) configuration interface does not properly sanitize user-supplied …

May 13, 2026
CVE-2026-34176
8.7 HIGH

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker …

May 13, 2026
CVE-2026-32673
8.7 HIGH

A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands …

May 13, 2026
CVE-2026-32643
8.7 HIGH

A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects …

May 13, 2026
CVE-2026-20916
8.1 HIGH

An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: …

May 13, 2026
CVE-2025-28344
7.5 HIGH

striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.

May 13, 2026
CVE-2025-28343
7.5 HIGH

striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.

May 13, 2026
CVE-2024-55045
7.3 HIGH

Firmament-Autopilot FMT-Firmware commit de5aec was discovered to contain a buffer overflow via the task_mavobc_entry function at /comm/task_comm.c.

May 13, 2026
CVE-2020-37226
7.1 HIGH

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' …

May 13, 2026
CVE-2020-37224
7.1 HIGH

Joomla J2 JOBS 1.3.0 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'sortby' …

May 13, 2026
CVE-2020-37223
7.8 HIGH

IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can …

May 13, 2026
CVE-2020-37222
7.2 HIGH

Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs …

May 13, 2026
CVE-2020-37221
8.4 HIGH

Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display …

May 13, 2026
CVE-2020-37220
7.5 HIGH

Huawei HG630 V2 router contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number. Attackers can …

May 13, 2026
CVE-2020-37219
7.5 HIGH

Joomla com_fabrik 3.9.11 contains a directory traversal vulnerability that allows unauthenticated attackers to list arbitrary files by manipulating the folder parameter. Attackers can send GET …

May 13, 2026
CVE-2020-37218
8.2 HIGH

Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code …

May 13, 2026
CVE-2026-4609
7.1 HIGH

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the pm_invite_user …

May 13, 2026
CVE-2026-37430
7.3 HIGH

An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.

May 13, 2026
CVE-2026-6177
7.2 HIGH

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient …

May 13, 2026
CVE-2026-3425
8.8 HIGH

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' …

May 13, 2026
CVE-2026-35506
7.2 HIGH

ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a …

May 13, 2026
CVE-2026-6276
7.5 HIGH

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy …

May 13, 2026
CVE-2026-5773
7.5 HIGH

libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers. libcurl features a pool of recent connections so that subsequent requests can reuse …

May 13, 2026
CVE-2026-4798
7.5 HIGH

The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due …

May 13, 2026
CVE-2026-25705
8.4 HIGH

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside …

May 13, 2026
CVE-2026-6929
7.5 HIGH

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' …

May 13, 2026
CVE-2026-44612
7.8 HIGH

Bytello Share (Windows Edition) installer executable provided by Bytello insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when …

May 13, 2026
CVE-2026-21020
7.8 HIGH

Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.

May 13, 2026
CVE-2026-7635
8.1 HIGH

The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is …

May 13, 2026
CVE-2026-8336
7.5 HIGH

After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently …

May 13, 2026
CVE-2026-8053
8.8 HIGH

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod …

May 13, 2026
CVE-2026-6888
7.2 HIGH

Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands via a specific interface, potentially enabling the attacker …

May 13, 2026
CVE-2026-8108
7.8 HIGH

The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions.

May 12, 2026
CVE-2026-5371
7.1 HIGH

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due …

May 12, 2026
CVE-2026-44548
8.1 HIGH

ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDelete.php causes a …

May 12, 2026
CVE-2026-43685
7.2 HIGH

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating system commands through unsanitized input …

May 12, 2026
CVE-2026-43680
7.2 HIGH

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule …

May 12, 2026
CVE-2026-42289
8.8 HIGH

ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF …

May 12, 2026
CVE-2026-1250
7.5 HIGH

The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in all versions …

May 12, 2026
CVE-2026-45227
8.8 HIGH

Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated workflow authors to bypass sandbox restrictions by using …

May 12, 2026
CVE-2026-45226
7.1 HIGH

Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without …

May 12, 2026
CVE-2026-45225
7.6 HIGH

Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write attacker-controlled files to arbitrary locations by …

May 12, 2026
CVE-2026-44871
7.2 HIGH

Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of …

May 12, 2026
CVE-2026-44304
8.1 HIGH

Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. …

May 12, 2026
CVE-2026-44302
7.5 HIGH

Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStream enters an uncatchable infinite loop when decompressing a malformed …

May 12, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.