CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-71300
9.8 CRITICAL

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 …

Aug 24, 2026
CVE-2026-66906
9.1 CRITICAL

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from …

Aug 24, 2026
CVE-2026-76071
9.8 CRITICAL

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized …

Aug 24, 2026
CVE-2026-76070
9.8 CRITICAL

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized …

Aug 24, 2026
CVE-2026-19874
9.1 CRITICAL

A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The …

Aug 24, 2026
CVE-2026-76840
9.6 CRITICAL

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as …

Aug 24, 2026
CVE-2026-67602
9.1 CRITICAL

phpIPAM before 1.8.2 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to gain full API access by exploiting an insecure …

Aug 24, 2026
CVE-2026-59568
9.1 CRITICAL

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in …

Aug 24, 2026
CVE-2026-59564
9.1 CRITICAL

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

Aug 24, 2026
CVE-2026-66650
9.8 CRITICAL

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

Aug 24, 2026
CVE-2026-66648
9.8 CRITICAL

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

Aug 24, 2026
CVE-2026-66587
9.8 CRITICAL

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Aug 24, 2026
CVE-2026-32558
9.8 CRITICAL

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

Aug 24, 2026
CVE-2026-32551
9.3 CRITICAL

Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

Aug 24, 2026
CVE-2026-28165
9.8 CRITICAL

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

Aug 24, 2026
CVE-2026-66897
9.9 CRITICAL

A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite …

Aug 24, 2026
CVE-2026-78211
9.8 CRITICAL

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb …

Aug 24, 2026
CVE-2026-78169
9.9 CRITICAL

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request …

Aug 24, 2026
CVE-2026-78168
9.8 CRITICAL

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such …

Aug 24, 2026
CVE-2026-78167
10.0 CRITICAL

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation …

Aug 24, 2026
CVE-2026-78207
9.4 CRITICAL

exceljs through 4.4.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. …

Aug 24, 2026
CVE-2026-78183
9.8 CRITICAL

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size …

Aug 23, 2026
CVE-2026-8445
9.8 CRITICAL

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown …

Aug 23, 2026
CVE-2026-7808
9.8 CRITICAL

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site …

Aug 23, 2026
CVE-2026-5388
9.8 CRITICAL

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Depending on …

Aug 23, 2026
CVE-2026-78155
9.9 CRITICAL

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Aug 23, 2026
CVE-2026-13598
9.8 CRITICAL

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account …

Aug 23, 2026
CVE-2026-78050
9.9 CRITICAL

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The …

Aug 23, 2026
CVE-2026-74730
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was …

Aug 22, 2026
CVE-2026-74727
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by_id ovpn_nl_peer_set_doit() resolves the target peer via …

Aug 22, 2026
CVE-2026-74723
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the …

Aug 22, 2026
CVE-2026-74712
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: Fix buffer length in create_direct_keys() We have seen in our CI the following KASAN …

Aug 22, 2026
CVE-2026-74705
10.0 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the …

Aug 22, 2026
CVE-2026-74688
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being removed sctp_make_heartbeat_ack() caches the destination transport …

Aug 22, 2026
CVE-2026-74669
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP errors ip_vs_in_icmp() rebases an skb from the …

Aug 22, 2026
CVE-2026-74665
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: fix skb length accounting after generic XDP frag adjustment Generic XDP exposes non-linear skb …

Aug 22, 2026
CVE-2026-74662
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer inet_frag_create() arms the fragment queue timer before inserting …

Aug 22, 2026
CVE-2026-74628
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its timers The x25 timers are armed with …

Aug 22, 2026
CVE-2026-74617
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: dibs: initialise dibs->lock in dibs_dev_alloc() dibs->lock is initialised by dibs_dev_add(), but a dibs device can …

Aug 22, 2026
CVE-2026-74616
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_info tailroom xdpf_clone() clones broadcast copies into a single page …

Aug 22, 2026
CVE-2026-74612
10.0 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: veth: fix skb length accounting after XDP frag adjustment veth exposes non-linear skb fragments through …

Aug 22, 2026
CVE-2026-74611
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic retry tls_decrypt_sg() advances msg->msg_iter when it maps …

Aug 22, 2026
CVE-2026-74608
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_adding_channels() cifs_try_adding_channels() takes a temporary reference to an interface before …

Aug 22, 2026
CVE-2026-74597
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it …

Aug 22, 2026
CVE-2026-74591
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index before retrying In __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is applied repeatedly: each …

Aug 22, 2026
CVE-2026-74588
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list it is queued on __sctp_outq_flush_rtx() moves a …

Aug 22, 2026
CVE-2026-74587
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk addip_last_asconf caches the outstanding outbound ASCONF chunk. The …

Aug 22, 2026
CVE-2026-74586
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in …

Aug 22, 2026
CVE-2026-4703
9.8 CRITICAL

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …

Aug 22, 2026
CVE-2026-75870
9.1 CRITICAL

Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The …

Aug 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.