CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-51002

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2022-51001

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-48005

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-48004

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-48003

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-48002

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-48001

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-48000

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-47999

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-47998

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2021-47997

Rejected reason: This CVE ID has been rejected.

Aug 27, 2026
CVE-2026-81814

Affected versions of Flowintel render calendar event titles using innerHTML. Because those titles are derived from case titles, a user able to create or modify …

Aug 27, 2026
CVE-2026-81753

Affected versions of Flowintel render Mermaid blocks contained in stored case notes without sufficiently neutralizing attacker-controlled markup. Because Mermaid note content is persisted and later …

Aug 27, 2026
CVE-2026-81743

Affected versions of Flowintel allow the LOG_FILE configuration value to be modified through system settings without restricting it to a filename inside the intended log …

Aug 27, 2026
CVE-2026-81677

The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks …

Aug 27, 2026
CVE-2026-81676

A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting …

Aug 27, 2026
CVE-2026-81675

The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping …

Aug 27, 2026
CVE-2026-81674

The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject …

Aug 27, 2026
CVE-2026-81673

The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including …

Aug 27, 2026
CVE-2026-81672

SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, …

Aug 27, 2026
CVE-2026-81668
5.4 MEDIUM

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An …

Aug 27, 2026
CVE-2026-81662

Affected versions of Flowintel improperly trust configuration keys supplied to the alerts settings update endpoint. While configuration values were normalized to Python literals, the corresponding …

Aug 27, 2026
CVE-2026-81659

Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local …

Aug 27, 2026
CVE-2026-81658
6.5 MEDIUM

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged …

Aug 27, 2026
CVE-2026-81562
5.3 MEDIUM

A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os …

Aug 27, 2026
CVE-2026-81560
5.3 MEDIUM

A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component …

Aug 27, 2026
CVE-2026-74233
9.8 CRITICAL

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, …

Aug 27, 2026
CVE-2026-74232
9.8 CRITICAL

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, …

Aug 27, 2026
CVE-2026-66155
7.6 HIGH

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions …

Aug 27, 2026
CVE-2026-5218
4.3 MEDIUM

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting …

Aug 27, 2026
CVE-2026-17562
6.5 MEDIUM

Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: before v5.21.0.

Aug 27, 2026
CVE-2026-81625
8.8 HIGH

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer …

Aug 27, 2026
CVE-2026-81581
8.8 HIGH

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside …

Aug 27, 2026
CVE-2026-81579
8.8 HIGH

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a …

Aug 27, 2026
CVE-2026-81576
7.7 HIGH

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole …

Aug 27, 2026
CVE-2026-81575
7.5 HIGH

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data …

Aug 27, 2026
CVE-2026-81574
8.2 HIGH

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format …

Aug 27, 2026
CVE-2026-81573
8.6 HIGH

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only …

Aug 27, 2026
CVE-2026-81572
7.8 HIGH

In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. …

Aug 27, 2026
CVE-2026-81279
5.4 MEDIUM

Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.

Aug 27, 2026
CVE-2026-81277
8.5 HIGH

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

Aug 27, 2026
CVE-2026-81276
5.3 MEDIUM

Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions.

Aug 27, 2026
CVE-2026-81274
5.3 MEDIUM

Subscriber Broken Access Control in Ditty <= 3.1.67 versions.

Aug 27, 2026
CVE-2026-81273
8.1 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

Aug 27, 2026
CVE-2026-81272
4.9 MEDIUM

Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.

Aug 27, 2026
CVE-2026-81271
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

Aug 27, 2026
CVE-2026-80433
7.5 HIGH

Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.

Aug 27, 2026
CVE-2026-78293
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

Aug 27, 2026
CVE-2026-78292
9.8 CRITICAL

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

Aug 27, 2026
CVE-2026-78289
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

Aug 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.