CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78939
9.6 CRITICAL

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code …

Aug 25, 2026
CVE-2026-78937
9.6 CRITICAL

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary …

Aug 25, 2026
CVE-2026-78935
9.6 CRITICAL

Use of uninitialized variable in Mobile in Google Chrome on on iOS prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside …

Aug 25, 2026
CVE-2026-78909
9.6 CRITICAL

Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Aug 25, 2026
CVE-2026-78904
9.6 CRITICAL

Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted …

Aug 25, 2026
CVE-2026-78900
9.6 CRITICAL

Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Aug 25, 2026
CVE-2026-65093
9.9 CRITICAL

NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code …

Aug 25, 2026
CVE-2026-65083
9.9 CRITICAL

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful …

Aug 25, 2026
CVE-2026-51368
9.8 CRITICAL

An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted …

Aug 25, 2026
CVE-2026-45018
9.8 CRITICAL

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose …

Aug 25, 2026
CVE-2026-79787
9.8 CRITICAL

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can …

Aug 25, 2026
CVE-2026-76197
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result …

Aug 25, 2026
CVE-2026-76195
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result …

Aug 25, 2026
CVE-2026-76193
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the …

Aug 25, 2026
CVE-2026-79675
9.8 CRITICAL

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. …

Aug 25, 2026
CVE-2026-55640
9.1 CRITICAL

Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py …

Aug 25, 2026
CVE-2026-55546
9.8 CRITICAL

QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after …

Aug 25, 2026
CVE-2026-55536
9.1 CRITICAL

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra …

Aug 25, 2026
CVE-2025-71407
9.8 CRITICAL

Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors with long QName prefixes, and a use-after-free vulnerability during …

Aug 25, 2026
CVE-2024-58378
9.8 CRITICAL

Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader …

Aug 25, 2026
CVE-2022-51000
9.8 CRITICAL

Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in …

Aug 25, 2026
CVE-2026-16286
9.8 CRITICAL

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload …

Aug 25, 2026
CVE-2026-63073
9.8 CRITICAL

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or …

Aug 25, 2026
CVE-2026-79657
9.8 CRITICAL

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers …

Aug 25, 2026
CVE-2026-55976
9.1 CRITICAL

Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause …

Aug 25, 2026
CVE-2026-49845
9.8 CRITICAL

SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore …

Aug 25, 2026
CVE-2026-78570
9.8 CRITICAL

The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated …

Aug 25, 2026
CVE-2026-78568
9.8 CRITICAL

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the …

Aug 25, 2026
CVE-2026-63586
9.8 CRITICAL

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without …

Aug 25, 2026
CVE-2026-59769
9.1 CRITICAL

FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen …

Aug 25, 2026
CVE-2026-78477
9.8 CRITICAL

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers …

Aug 25, 2026
CVE-2026-13214
9.8 CRITICAL

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied …

Aug 25, 2026
CVE-2026-78683
9.6 CRITICAL

NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the default restricted=False, …

Aug 25, 2026
CVE-2026-78676
9.8 CRITICAL

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft …

Aug 25, 2026
CVE-2026-56710
9.8 CRITICAL

Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can …

Aug 25, 2026
CVE-2026-56705
9.8 CRITICAL

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers …

Aug 25, 2026
CVE-2026-78267
9.8 CRITICAL

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

Aug 24, 2026
CVE-2026-78265
9.8 CRITICAL

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

Aug 24, 2026
CVE-2026-78262
9.8 CRITICAL

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

Aug 24, 2026
CVE-2026-32563
9.8 CRITICAL

Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

Aug 24, 2026
CVE-2026-32559
9.9 CRITICAL

Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

Aug 24, 2026
CVE-2026-32555
9.3 CRITICAL

Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

Aug 24, 2026
CVE-2026-32554
9.3 CRITICAL

Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

Aug 24, 2026
CVE-2026-52490
9.8 CRITICAL

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

Aug 24, 2026
CVE-2026-76835
9.1 CRITICAL

OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the …

Aug 24, 2026
CVE-2026-71933
9.1 CRITICAL

Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger …

Aug 24, 2026
CVE-2026-71921
9.8 CRITICAL

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field …

Aug 24, 2026
CVE-2026-71914
9.8 CRITICAL

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after …

Aug 24, 2026
CVE-2026-78329
9.8 CRITICAL

Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before …

Aug 24, 2026
CVE-2026-77915
9.8 CRITICAL

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.