CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-80589
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a never added disk disk_release() undoes blk_mq_init_allocated_queue() for …

Aug 26, 2026
CVE-2026-80587
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the …

Aug 26, 2026
CVE-2026-80586
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send …

Aug 26, 2026
CVE-2026-80585
9.4 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a …

Aug 26, 2026
CVE-2026-80561
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_locker() decode_locker() in cls_lock_client.c contains three unsafe decode operations …

Aug 26, 2026
CVE-2026-80558
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from primary_temp A corrupted osdmap received from a Ceph …

Aug 26, 2026
CVE-2026-80557
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via missing bounds check ceph_start_decoding() validates that struct_len bytes …

Aug 26, 2026
CVE-2026-80554
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Limit the number of channel program segments The processing of channel programs, and the …

Aug 26, 2026
CVE-2026-80551
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Ensure first IDAW remains constant The first IDAW in a list does not need …

Aug 26, 2026
CVE-2026-80528
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_info` while …

Aug 26, 2026
CVE-2026-80519
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer release Crypto completion callbacks hold both key-slot and …

Aug 26, 2026
CVE-2026-74752
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When cookie authentication is disabled, COOKIE_ECHO restores fixed-size …

Aug 26, 2026
CVE-2026-74751
9.4 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: riscv: lib: Fix ZBB strnlen reading past count boundary The ZBB-optimized strnlen loop loads one …

Aug 26, 2026
CVE-2026-74746
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. …

Aug 26, 2026
CVE-2026-74744
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), …

Aug 26, 2026
CVE-2026-74743
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroom from lowerdev macvlan devices inherit hard_header_len from lowerdev during macvlan_init(), …

Aug 26, 2026
CVE-2026-74737
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG On the packet reception path, …

Aug 26, 2026
CVE-2026-54523
9.6 CRITICAL

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to …

Aug 26, 2026
CVE-2026-75896
9.1 CRITICAL

Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords. This issue affects Liderahenk: …

Aug 26, 2026
CVE-2026-80203
9.8 CRITICAL

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() …

Aug 26, 2026
CVE-2026-77557
9.8 CRITICAL

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on …

Aug 26, 2026
CVE-2026-77554
10.0 CRITICAL

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection …

Aug 26, 2026
CVE-2026-77553
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate …

Aug 26, 2026
CVE-2026-77552
9.8 CRITICAL

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command …

Aug 26, 2026
CVE-2026-77551
9.0 CRITICAL

A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast …

Aug 26, 2026
CVE-2026-77550
10.0 CRITICAL

A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to …

Aug 26, 2026
CVE-2026-77549
9.0 CRITICAL

A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices …

Aug 26, 2026
CVE-2026-77548
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute …

Aug 26, 2026
CVE-2026-77547
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Aug 26, 2026
CVE-2026-77546
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Aug 26, 2026
CVE-2026-77532
9.6 CRITICAL

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote …

Aug 26, 2026
CVE-2026-18080
9.8 CRITICAL

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up …

Aug 26, 2026
CVE-2026-80349
9.8 CRITICAL

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which …

Aug 26, 2026
CVE-2026-77545
9.0 CRITICAL

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices …

Aug 26, 2026
CVE-2026-77543
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Aug 26, 2026
CVE-2026-77542
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute …

Aug 26, 2026
CVE-2026-77541
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate …

Aug 26, 2026
CVE-2026-77540
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute …

Aug 26, 2026
CVE-2026-77539
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute …

Aug 26, 2026
CVE-2026-77537
10.0 CRITICAL

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection …

Aug 26, 2026
CVE-2026-77536
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS …

Aug 26, 2026
CVE-2026-77535
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute …

Aug 26, 2026
CVE-2026-77534
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS …

Aug 26, 2026
CVE-2026-59683
9.8 CRITICAL

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise …

Aug 26, 2026
CVE-2026-59682
9.1 CRITICAL

Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

Aug 26, 2026
CVE-2026-80235
9.8 CRITICAL

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary …

Aug 26, 2026
CVE-2026-77533
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute …

Aug 26, 2026
CVE-2026-18431
9.8 CRITICAL

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is …

Aug 26, 2026
CVE-2026-19632
9.8 CRITICAL

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Aug 26, 2026
CVE-2026-80138
9.8 CRITICAL

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.