CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-77548
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute …

Aug 26, 2026
CVE-2026-77547
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Aug 26, 2026
CVE-2026-77546
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Aug 26, 2026
CVE-2026-77532
9.6 CRITICAL

A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote …

Aug 26, 2026
CVE-2026-5092
6.4 MEDIUM

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up …

Aug 26, 2026
CVE-2026-3235
5.3 MEDIUM

The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' …

Aug 26, 2026
CVE-2026-18080
9.8 CRITICAL

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up …

Aug 26, 2026
CVE-2026-80350
7.1 HIGH

OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for …

Aug 26, 2026
CVE-2026-80349
9.8 CRITICAL

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which …

Aug 26, 2026
CVE-2026-80348
8.8 HIGH

TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call. uploadAndPublish accepts a package …

Aug 26, 2026
CVE-2026-80347
7.5 HIGH

mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed …

Aug 26, 2026
CVE-2026-80346
7.1 HIGH

StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, …

Aug 26, 2026
CVE-2026-77545
9.0 CRITICAL

A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices …

Aug 26, 2026
CVE-2026-77543
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Aug 26, 2026
CVE-2026-77542
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute …

Aug 26, 2026
CVE-2026-77541
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate …

Aug 26, 2026
CVE-2026-77540
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute …

Aug 26, 2026
CVE-2026-77539
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute …

Aug 26, 2026
CVE-2026-77538
8.2 HIGH

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the …

Aug 26, 2026
CVE-2026-77537
10.0 CRITICAL

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection …

Aug 26, 2026
CVE-2026-77536
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS …

Aug 26, 2026
CVE-2026-77535
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute …

Aug 26, 2026
CVE-2026-77534
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS …

Aug 26, 2026
CVE-2026-59683
9.8 CRITICAL

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise …

Aug 26, 2026
CVE-2026-59682
9.1 CRITICAL

Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

Aug 26, 2026
CVE-2026-2388
6.4 MEDIUM

The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.10. This …

Aug 26, 2026
CVE-2026-19042
8.8 HIGH

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in …

Aug 26, 2026
CVE-2026-18794
8.2 HIGH

The OpenRGB network protocol allows attackers to cause memory exhaustion and out-of-bounds memory reads and writes by passing inconsistent data.

Aug 26, 2026
CVE-2026-16444
7.5 HIGH

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations …

Aug 26, 2026
CVE-2026-80237
8.8 HIGH

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary …

Aug 26, 2026
CVE-2026-80236
8.2 HIGH

Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents.

Aug 26, 2026
CVE-2026-80235
9.8 CRITICAL

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary …

Aug 26, 2026
CVE-2026-80234
5.3 MEDIUM

CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting …

Aug 26, 2026
CVE-2026-80233
7.2 HIGH

CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web …

Aug 26, 2026
CVE-2026-77533
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute …

Aug 26, 2026
CVE-2026-19538

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over …

Aug 26, 2026
CVE-2026-19401

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of …

Aug 26, 2026
CVE-2026-19197
6.3 MEDIUM

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret …

Aug 26, 2026
CVE-2026-18916

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, …

Aug 26, 2026
CVE-2026-18664

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian …

Aug 26, 2026
CVE-2026-9668
6.3 MEDIUM

With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently …

Aug 26, 2026
CVE-2026-78237
7.8 HIGH

Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective …

Aug 26, 2026
CVE-2026-78236
8.8 HIGH

An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as …

Aug 26, 2026
CVE-2026-75977
8.8 HIGH

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This …

Aug 26, 2026
CVE-2026-6178
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's 'icon_box_2' shortcode in all versions up to, and including, 28.4 due …

Aug 26, 2026
CVE-2026-18884
7.5 HIGH

The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, …

Aug 26, 2026
CVE-2026-58108

The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no join between them. SQLAlchemy resolves that as an …

Aug 26, 2026
CVE-2026-3002
6.4 MEDIUM

The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all …

Aug 26, 2026
CVE-2026-18431
9.8 CRITICAL

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is …

Aug 26, 2026
CVE-2026-18331
7.2 HIGH

The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.