CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18056
7.5 HIGH

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is …

Sep 6, 2026
CVE-2026-16310
9.8 CRITICAL

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due …

Sep 6, 2026
CVE-2026-86153
9.1 CRITICAL

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. …

Sep 6, 2026
CVE-2026-86152
10.0 CRITICAL

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing …

Sep 6, 2026
CVE-2026-86151
9.1 CRITICAL

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. …

Sep 6, 2026
CVE-2026-86150
4.1 MEDIUM

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase …

Sep 5, 2026
CVE-2026-76161

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 5, 2026
CVE-2026-76160

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 5, 2026
CVE-2026-86149
9.1 CRITICAL

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host …

Sep 5, 2026
CVE-2026-86148
9.1 CRITICAL

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The …

Sep 5, 2026
CVE-2026-86206

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

Sep 5, 2026
CVE-2026-86060
9.8 CRITICAL KEV

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask …

Sep 5, 2026
CVE-2026-67281

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file …

Sep 5, 2026
CVE-2026-67279

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session …

Sep 5, 2026
CVE-2026-67278

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an …

Sep 5, 2026
CVE-2026-67277
8.2 HIGH KEV

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 …

Sep 5, 2026
CVE-2026-67276

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and …

Sep 5, 2026
CVE-2026-86207

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

Sep 5, 2026
CVE-2026-6554
5.5 MEDIUM

libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does …

Sep 5, 2026
CVE-2026-6244
5.5 MEDIUM

libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use …

Sep 5, 2026
CVE-2026-31912
5.5 MEDIUM

libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction …

Sep 5, 2026
CVE-2026-31911
5.5 MEDIUM

libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program …

Sep 5, 2026
CVE-2026-18313
4.3 MEDIUM

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it …

Sep 5, 2026
CVE-2026-18238
5.0 MEDIUM

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message …

Sep 5, 2026
CVE-2026-0799
8.7 HIGH

In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, …

Sep 5, 2026
CVE-2026-82752

Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose …

Sep 5, 2026
CVE-2026-86197

Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. …

Sep 5, 2026
CVE-2026-86196

Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset …

Sep 5, 2026
CVE-2026-86195

grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip …

Sep 5, 2026
CVE-2026-86194

Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined …

Sep 5, 2026
CVE-2026-86193

grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write …

Sep 5, 2026
CVE-2026-86192
6.5 MEDIUM

SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows …

Sep 5, 2026
CVE-2026-86191
4.3 MEDIUM

SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without …

Sep 5, 2026
CVE-2026-86190
9.1 CRITICAL

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers …

Sep 5, 2026
CVE-2026-86189
9.8 CRITICAL

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in …

Sep 5, 2026
CVE-2026-86188
7.2 HIGH

AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback …

Sep 5, 2026
CVE-2026-86187
5.9 MEDIUM

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can …

Sep 5, 2026
CVE-2026-86186
6.5 MEDIUM

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force …

Sep 5, 2026
CVE-2026-86185
8.0 HIGH

Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position …

Sep 5, 2026
CVE-2026-86184
9.8 CRITICAL

Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when …

Sep 5, 2026
CVE-2026-15550
4.3 MEDIUM

The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to …

Sep 5, 2026
CVE-2026-12843
5.4 MEDIUM

The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying …

Sep 5, 2026
CVE-2026-10196
9.8 CRITICAL

The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Sep 5, 2026
CVE-2025-9049
8.8 HIGH

The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Sep 5, 2026
CVE-2025-15647
5.5 MEDIUM

CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent …

Sep 5, 2026
CVE-2025-15614
3.3 LOW

ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files …

Sep 5, 2026
CVE-2026-86178
5.4 MEDIUM

Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential …

Sep 5, 2026
CVE-2026-86177
8.8 HIGH

Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers …

Sep 5, 2026
CVE-2026-86176
4.3 MEDIUM

NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions …

Sep 5, 2026
CVE-2026-86175
6.5 MEDIUM

NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve …

Sep 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.