CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-75971
7.2 HIGH

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, …

Aug 25, 2026
CVE-2026-75908
4.3 MEDIUM

The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not …

Aug 25, 2026
CVE-2026-57910

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

Aug 25, 2026
CVE-2026-57909

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

Aug 25, 2026
CVE-2026-19949
8.8 HIGH

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, …

Aug 25, 2026
CVE-2026-18547
6.4 MEDIUM

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Aug 25, 2026
CVE-2026-17587
5.3 MEDIUM

The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and …

Aug 25, 2026
CVE-2026-79652
5.9 MEDIUM

A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various …

Aug 25, 2026
CVE-2026-78863
6.3 MEDIUM

A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. …

Aug 25, 2026
CVE-2026-59335
8.7 HIGH

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated …

Aug 25, 2026
CVE-2026-55976
9.1 CRITICAL

Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause …

Aug 25, 2026
CVE-2026-53561
7.4 HIGH

An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with …

Aug 25, 2026
CVE-2026-49845
9.8 CRITICAL

SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore …

Aug 25, 2026
CVE-2026-21758
3.7 LOW

HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.

Aug 25, 2026
CVE-2026-21754
5.4 MEDIUM

HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within …

Aug 25, 2026
CVE-2026-21753
4.2 MEDIUM

HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the …

Aug 25, 2026
CVE-2026-12600

Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF …

Aug 25, 2026
CVE-2026-78576
7.5 HIGH

The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied …

Aug 25, 2026
CVE-2026-78572
8.1 HIGH

The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. …

Aug 25, 2026
CVE-2026-78570
9.8 CRITICAL

The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated …

Aug 25, 2026
CVE-2026-76128
6.4 MEDIUM

The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 …

Aug 25, 2026
CVE-2026-75038
6.1 MEDIUM

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.

Aug 25, 2026
CVE-2026-75037
7.0 HIGH

Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit …

Aug 25, 2026
CVE-2026-49050
8.8 HIGH

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which …

Aug 25, 2026
CVE-2026-16231
8.1 HIGH

hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during …

Aug 25, 2026
CVE-2026-12878

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

Aug 25, 2026
CVE-2026-78568
9.8 CRITICAL

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the …

Aug 25, 2026
CVE-2026-78566
8.1 HIGH

The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated …

Aug 25, 2026
CVE-2026-78563
7.2 HIGH

The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization …

Aug 25, 2026
CVE-2026-78562
8.1 HIGH

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for …

Aug 25, 2026
CVE-2026-77146

The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to …

Aug 25, 2026
CVE-2026-77145

The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with …

Aug 25, 2026
CVE-2026-77144

The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. …

Aug 25, 2026
CVE-2026-77143

The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a …

Aug 25, 2026
CVE-2026-77142

The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, …

Aug 25, 2026
CVE-2026-77141

The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check …

Aug 25, 2026
CVE-2026-77140

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that …

Aug 25, 2026
CVE-2026-77139

The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An …

Aug 25, 2026
CVE-2026-77138

The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted …

Aug 25, 2026
CVE-2026-77137

The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary …

Aug 25, 2026
CVE-2026-77136

The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View …

Aug 25, 2026
CVE-2026-77135

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to …

Aug 25, 2026
CVE-2026-77134

The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor …

Aug 25, 2026
CVE-2026-77133

The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default …

Aug 25, 2026
CVE-2026-77131

When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already …

Aug 25, 2026
CVE-2026-77130

The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate …

Aug 25, 2026
CVE-2026-77129

The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event …

Aug 25, 2026
CVE-2026-77128

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or …

Aug 25, 2026
CVE-2026-77127

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, …

Aug 25, 2026
CVE-2026-63587
8.6 HIGH

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry …

Aug 25, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.