CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63509
9.9 CRITICAL

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-62834
9.3 CRITICAL

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

Aug 20, 2026
CVE-2026-18835
9.9 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of …

Aug 20, 2026
CVE-2026-17422
9.3 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.

Aug 20, 2026
CVE-2026-17160
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during …

Aug 20, 2026
CVE-2026-17157
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

Aug 20, 2026
CVE-2026-17152
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Aug 20, 2026
CVE-2026-17145
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.

Aug 20, 2026
CVE-2026-17142
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.

Aug 20, 2026
CVE-2026-17141
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Aug 20, 2026
CVE-2026-17136
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.

Aug 20, 2026
CVE-2026-17122
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

Aug 20, 2026
CVE-2026-17118
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.

Aug 20, 2026
CVE-2026-17040
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Aug 20, 2026
CVE-2026-71485
9.1 CRITICAL

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The …

Aug 20, 2026
CVE-2026-67567
9.9 CRITICAL

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass …

Aug 20, 2026
CVE-2026-43798
9.8 CRITICAL

A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. …

Aug 20, 2026
CVE-2026-77148
9.9 CRITICAL

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results …

Aug 20, 2026
CVE-2026-66788
9.9 CRITICAL

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection …

Aug 20, 2026
CVE-2026-66785
9.9 CRITICAL

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing …

Aug 20, 2026
CVE-2026-73257
9.1 CRITICAL

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length …

Aug 20, 2026
CVE-2026-73256
9.1 CRITICAL

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a …

Aug 20, 2026
CVE-2026-77022
9.9 CRITICAL

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component …

Aug 20, 2026
CVE-2026-71428
9.3 CRITICAL

The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 …

Aug 20, 2026
CVE-2026-55642
9.8 CRITICAL

dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash …

Aug 20, 2026
CVE-2026-18265
9.8 CRITICAL

OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is …

Aug 20, 2026
CVE-2026-63039
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value …

Aug 20, 2026
CVE-2026-63038
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code …

Aug 20, 2026
CVE-2026-63037
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER …

Aug 20, 2026
CVE-2026-16926
9.1 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special …

Aug 20, 2026
CVE-2026-15706
9.8 CRITICAL

Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue …

Aug 20, 2026
CVE-2026-28164
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.

Aug 20, 2026
CVE-2026-74018
9.9 CRITICAL

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

Aug 20, 2026
CVE-2026-74016
9.9 CRITICAL

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

Aug 20, 2026
CVE-2026-74014
9.9 CRITICAL

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

Aug 20, 2026
CVE-2026-74001
9.8 CRITICAL

Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

Aug 20, 2026
CVE-2026-73993
9.8 CRITICAL

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

Aug 20, 2026
CVE-2026-73992
9.9 CRITICAL

Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.

Aug 20, 2026
CVE-2026-68566
9.3 CRITICAL

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

Aug 20, 2026
CVE-2026-66682
9.8 CRITICAL

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

Aug 20, 2026
CVE-2026-66680
9.3 CRITICAL

Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

Aug 20, 2026
CVE-2026-66672
9.8 CRITICAL

Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

Aug 20, 2026
CVE-2026-66649
9.3 CRITICAL

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

Aug 20, 2026
CVE-2026-66609
9.3 CRITICAL

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

Aug 20, 2026
CVE-2026-66600
9.1 CRITICAL

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

Aug 20, 2026
CVE-2026-66593
9.3 CRITICAL

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

Aug 20, 2026
CVE-2026-66592
9.3 CRITICAL

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

Aug 20, 2026
CVE-2026-66583
9.8 CRITICAL

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

Aug 20, 2026
CVE-2025-15689
9.8 CRITICAL

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

Aug 20, 2026
CVE-2025-15688
9.3 CRITICAL

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

Aug 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.