CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78265
9.8 CRITICAL

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

Aug 24, 2026
CVE-2026-78264
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

Aug 24, 2026
CVE-2026-78263
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

Aug 24, 2026
CVE-2026-78262
9.8 CRITICAL

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

Aug 24, 2026
CVE-2026-78259
7.3 HIGH

Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

Aug 24, 2026
CVE-2026-77384
7.5 HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but …

Aug 24, 2026
CVE-2026-77337

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versions before 2.11.2, from 3.0.0 through 3.3.6, and …

Aug 24, 2026
CVE-2026-68516
6.5 MEDIUM

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a …

Aug 24, 2026
CVE-2026-45404

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a …

Aug 24, 2026
CVE-2026-32563
9.8 CRITICAL

Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

Aug 24, 2026
CVE-2026-32561
8.8 HIGH

Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

Aug 24, 2026
CVE-2026-32560
8.8 HIGH

Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.

Aug 24, 2026
CVE-2026-32559
9.9 CRITICAL

Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.

Aug 24, 2026
CVE-2026-32556
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

Aug 24, 2026
CVE-2026-32555
9.3 CRITICAL

Unauthenticated SQL Injection in Boost <= 2.0.4 versions.

Aug 24, 2026
CVE-2026-32554
9.3 CRITICAL

Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.

Aug 24, 2026
CVE-2026-27364
6.5 MEDIUM

Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

Aug 24, 2026
CVE-2026-17113
6.0 MEDIUM

A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI …

Aug 24, 2026
CVE-2026-7455
7.8 HIGH

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Aug 24, 2026
CVE-2026-77635

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable …

Aug 24, 2026
CVE-2026-77634

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers …

Aug 24, 2026
CVE-2026-77567
8.1 HIGH

Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication …

Aug 24, 2026
CVE-2026-75554

Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private …

Aug 24, 2026
CVE-2026-75542

Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. …

Aug 24, 2026
CVE-2026-75464
8.1 HIGH

OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().

Aug 24, 2026
CVE-2026-5006
6.8 MEDIUM

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated …

Aug 24, 2026
CVE-2026-56136
4.7 MEDIUM

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process …

Aug 24, 2026
CVE-2026-56135
7.4 HIGH

In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the …

Aug 24, 2026
CVE-2026-55468
4.3 MEDIUM

Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the …

Aug 24, 2026
CVE-2026-52492
7.8 HIGH

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based …

Aug 24, 2026
CVE-2026-52490
9.8 CRITICAL

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

Aug 24, 2026
CVE-2026-19568
7.8 HIGH

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to …

Aug 24, 2026
CVE-2026-16783
7.8 HIGH

A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Aug 24, 2026
CVE-2026-16782
5.3 MEDIUM

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to …

Aug 24, 2026
CVE-2026-16781
5.5 MEDIUM

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to …

Aug 24, 2026
CVE-2022-30983
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the …

Aug 24, 2026
CVE-2026-78555

RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Although the interface displayed only a shortened representation of each …

Aug 24, 2026
CVE-2026-78553

RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key file was created using the process's default permissions and umask, resulting …

Aug 24, 2026
CVE-2026-78551

RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust …

Aug 24, 2026
CVE-2026-78430
5.3 MEDIUM

A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall of the file src/tools/handlers.ts of the component Tool Handler. The manipulation of …

Aug 24, 2026
CVE-2026-77923
4.3 MEDIUM

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action …

Aug 24, 2026
CVE-2026-77310
5.3 MEDIUM

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prior to versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1 on their respective release …

Aug 24, 2026
CVE-2026-76816
3.5 LOW

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.137.Final and 4.2.17.Final, MqttEncoder does not validate client identifiers, will topics, usernames, and PUBLISH …

Aug 24, 2026
CVE-2026-76098
7.5 HIGH

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates …

Aug 24, 2026
CVE-2026-75509
6.5 MEDIUM

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership …

Aug 24, 2026
CVE-2026-75369
7.1 HIGH

An out-of-bounds read vulnerability in the CAN::Application::parsePerformFunctionMessage component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via …

Aug 24, 2026
CVE-2026-75368
7.5 HIGH

A stack overflow in the loadRawData function of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying …

Aug 24, 2026
CVE-2026-72714
6.3 MEDIUM

Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local …

Aug 24, 2026
CVE-2026-72711
6.3 MEDIUM

The Lean 4 kernel does not check that the body of an opaque declaration is closed. environment::add_opaque omits the check_no_metavar_no_fvar call that the definition and …

Aug 24, 2026
CVE-2026-72705
6.3 MEDIUM

The guard checker in Rocq Prover does not follow recursive calls made through a fixpoint's own arguments. A fixpoint may pass itself as a higher-order …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.