CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-75866
9.1 CRITICAL

Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers …

Aug 22, 2026
CVE-2026-77946
10.0 CRITICAL

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone …

Aug 22, 2026
CVE-2026-78003
9.8 CRITICAL

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This …

Aug 22, 2026
CVE-2026-77002
9.8 CRITICAL

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users …

Aug 22, 2026
CVE-2026-77001
9.8 CRITICAL

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one …

Aug 22, 2026
CVE-2026-77000
9.8 CRITICAL

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating …

Aug 22, 2026
CVE-2026-49849
9.1 CRITICAL

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files …

Aug 21, 2026
CVE-2026-76904
9.8 CRITICAL

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, …

Aug 21, 2026
CVE-2026-62283
9.9 CRITICAL

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind …

Aug 21, 2026
CVE-2026-61539
10.0 CRITICAL

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in …

Aug 21, 2026
CVE-2026-77810
9.9 CRITICAL

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute …

Aug 21, 2026
CVE-2026-62674
9.0 CRITICAL

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but …

Aug 21, 2026
CVE-2026-74581
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but …

Aug 21, 2026
CVE-2026-69502
10.0 CRITICAL

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Aug 21, 2026
CVE-2026-77087
9.6 CRITICAL

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft …

Aug 21, 2026
CVE-2026-63343
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host …

Aug 21, 2026
CVE-2026-63125
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and …

Aug 21, 2026
CVE-2026-62941
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs …

Aug 21, 2026
CVE-2026-62940
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including …

Aug 21, 2026
CVE-2026-62867
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument …

Aug 21, 2026
CVE-2026-48769
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious …

Aug 21, 2026
CVE-2026-48755
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in …

Aug 21, 2026
CVE-2026-48753
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows …

Aug 21, 2026
CVE-2026-48752
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read …

Aug 21, 2026
CVE-2026-48751
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on …

Aug 21, 2026
CVE-2026-48750
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the …

Aug 21, 2026
CVE-2026-48749
9.9 CRITICAL

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary …

Aug 21, 2026
CVE-2026-77806
9.8 CRITICAL

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection …

Aug 21, 2026
CVE-2026-77776
9.1 CRITICAL

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat …

Aug 21, 2026
CVE-2026-77683
9.9 CRITICAL

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of …

Aug 21, 2026
CVE-2026-77086
9.1 CRITICAL

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal …

Aug 21, 2026
CVE-2026-62440
9.1 CRITICAL

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue …

Aug 21, 2026
CVE-2026-61398
9.1 CRITICAL

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through …

Aug 21, 2026
CVE-2026-59085
9.1 CRITICAL

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and …

Aug 21, 2026
CVE-2026-77264
9.8 CRITICAL

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, …

Aug 21, 2026
CVE-2026-77651
9.8 CRITICAL

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue …

Aug 21, 2026
CVE-2026-77650
9.8 CRITICAL

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue …

Aug 21, 2026
CVE-2026-77649
9.8 CRITICAL

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue …

Aug 21, 2026
CVE-2026-77647
9.8 CRITICAL

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification …

Aug 20, 2026
CVE-2026-72843
9.8 CRITICAL

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the …

Aug 20, 2026
CVE-2026-69851
9.9 CRITICAL

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-69836
10.0 CRITICAL

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Aug 20, 2026
CVE-2026-69555
10.0 CRITICAL

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-69400
9.6 CRITICAL

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-68789
9.9 CRITICAL

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a …

Aug 20, 2026
CVE-2026-68782
9.9 CRITICAL

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a …

Aug 20, 2026
CVE-2026-66309
9.1 CRITICAL

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-65816
10.0 CRITICAL

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-65801
10.0 CRITICAL

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-65770
10.0 CRITICAL

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over …

Aug 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.