CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-13761

Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial …

Aug 28, 2026
CVE-2026-82261
7.5 HIGH

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send …

Aug 28, 2026
CVE-2026-82260
7.5 HIGH

SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form …

Aug 28, 2026
CVE-2026-82259
7.5 HIGH

SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions …

Aug 28, 2026
CVE-2026-82258
4.8 MEDIUM

SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request …

Aug 28, 2026
CVE-2026-82257
4.3 MEDIUM

SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can …

Aug 28, 2026
CVE-2026-82256
5.3 MEDIUM

SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation …

Aug 28, 2026
CVE-2026-82255
6.8 MEDIUM

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. …

Aug 28, 2026
CVE-2026-82254
7.5 HIGH

gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data …

Aug 28, 2026
CVE-2026-82253
7.5 HIGH

gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the …

Aug 28, 2026
CVE-2026-82252
7.5 HIGH

gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious …

Aug 28, 2026
CVE-2026-82251
7.5 HIGH

gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names …

Aug 28, 2026
CVE-2026-82250
6.5 MEDIUM

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious …

Aug 28, 2026
CVE-2026-82249
3.1 LOW

gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to …

Aug 28, 2026
CVE-2026-82248
5.3 MEDIUM

gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: …

Aug 28, 2026
CVE-2026-82247
7.5 HIGH

gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, …

Aug 28, 2026
CVE-2026-82246
7.1 HIGH

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers …

Aug 28, 2026
CVE-2026-82245
8.1 HIGH

Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers …

Aug 28, 2026
CVE-2026-82244
9.1 CRITICAL

Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a …

Aug 28, 2026
CVE-2026-82243
7.6 HIGH

Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF …

Aug 28, 2026
CVE-2026-82242
7.7 HIGH

Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens …

Aug 28, 2026
CVE-2026-82241
7.1 HIGH

Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query …

Aug 28, 2026
CVE-2026-82240
8.1 HIGH

Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant …

Aug 28, 2026
CVE-2026-82239
8.1 HIGH

Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows …

Aug 28, 2026
CVE-2026-82238
3.1 LOW

filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending …

Aug 28, 2026
CVE-2026-82237
3.1 LOW

filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by …

Aug 28, 2026
CVE-2026-82236
3.1 LOW

File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can …

Aug 28, 2026
CVE-2026-82235
5.9 MEDIUM

filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or …

Aug 28, 2026
CVE-2026-82234
8.2 HIGH

SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time …

Aug 28, 2026
CVE-2026-82233
5.7 MEDIUM

SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can …

Aug 28, 2026
CVE-2026-82222
10.0 CRITICAL

Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

Aug 28, 2026
CVE-2026-82111
4.3 MEDIUM

A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. …

Aug 28, 2026
CVE-2026-81777
5.3 MEDIUM

Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.

Aug 28, 2026
CVE-2026-81733

WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user …

Aug 28, 2026
CVE-2026-81732

WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send …

Aug 28, 2026
CVE-2026-78073

Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors

Aug 28, 2026
CVE-2026-78072

Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1

Aug 28, 2026
CVE-2026-78071

Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 - 10.11.2 - Location title is rendered in data attribute without escaping …

Aug 28, 2026
CVE-2026-78070

Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL …

Aug 28, 2026
CVE-2026-73209
6.5 MEDIUM

An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process …

Aug 28, 2026
CVE-2026-73208
7.4 HIGH

An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, …

Aug 28, 2026
CVE-2026-6128
6.4 MEDIUM

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and …

Aug 28, 2026
CVE-2026-5510
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up …

Aug 28, 2026
CVE-2026-52687
6.5 MEDIUM

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and …

Aug 28, 2026
CVE-2026-52681
3.1 LOW

Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the …

Aug 28, 2026
CVE-2026-42395
4.3 MEDIUM

A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. …

Aug 28, 2026
CVE-2026-42393
3.1 LOW

The comparison used for the doveadm password and API key is not fully timing safe and can reveal the length of the configured secret. An …

Aug 28, 2026
CVE-2026-42392
4.3 MEDIUM

An attacker that has valid credentials can send an invalid IMAP URLFETCH command, which causes uninitialized memory to be included in the error response returned …

Aug 28, 2026
CVE-2026-42391
7.5 HIGH

An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage …

Aug 28, 2026
CVE-2026-42008
4.3 MEDIUM

Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.