CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-20318
9.6 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. …

Aug 19, 2026
CVE-2026-20317
10.0 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. …

Aug 19, 2026
CVE-2026-20315
10.0 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. …

Aug 19, 2026
CVE-2026-20231
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. …

Aug 19, 2026
CVE-2026-20030
10.0 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This …

Aug 19, 2026
CVE-2026-71960
9.1 CRITICAL

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated …

Aug 19, 2026
CVE-2026-53451
9.8 CRITICAL

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command …

Aug 19, 2026
CVE-2026-52889
9.8 CRITICAL

Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer …

Aug 19, 2026
CVE-2026-47187
9.3 CRITICAL

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or …

Aug 19, 2026
CVE-2026-16816
9.9 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of …

Aug 19, 2026
CVE-2026-16656
9.8 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.

Aug 19, 2026
CVE-2026-15068
9.9 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization …

Aug 19, 2026
CVE-2026-15065
9.1 CRITICAL

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of …

Aug 19, 2026
CVE-2026-51366
9.9 CRITICAL

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter

Aug 19, 2026
CVE-2026-16019
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects …

Aug 19, 2026
CVE-2026-73391
9.3 CRITICAL

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

Aug 19, 2026
CVE-2026-73390
9.8 CRITICAL

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

Aug 19, 2026
CVE-2026-73389
9.8 CRITICAL

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

Aug 19, 2026
CVE-2026-73388
9.3 CRITICAL

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

Aug 19, 2026
CVE-2026-73364
9.8 CRITICAL

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

Aug 19, 2026
CVE-2026-73347
9.8 CRITICAL

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

Aug 19, 2026
CVE-2026-73185
9.3 CRITICAL

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

Aug 19, 2026
CVE-2026-73183
9.3 CRITICAL

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

Aug 19, 2026
CVE-2026-66613
9.8 CRITICAL

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

Aug 19, 2026
CVE-2026-71319
9.6 CRITICAL

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite …

Aug 5, 2026
CVE-2026-70615
9.9 CRITICAL

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH …

Aug 5, 2026
CVE-2026-48168
10.0 CRITICAL

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds …

Aug 5, 2026
CVE-2026-70426
9.0 CRITICAL

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to …

Aug 5, 2026
CVE-2026-20310
9.1 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20304
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20303
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20272
9.8 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20267
9.0 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-9195
9.3 CRITICAL

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator …

Aug 5, 2026
CVE-2026-9193
9.9 CRITICAL

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop …

Aug 5, 2026
CVE-2026-9192
9.8 CRITICAL

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password …

Aug 5, 2026
CVE-2026-9190
9.1 CRITICAL

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication …

Aug 5, 2026
CVE-2026-8709
9.9 CRITICAL

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with …

Aug 5, 2026
CVE-2026-7557
9.1 CRITICAL

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker …

Aug 5, 2026
CVE-2026-7329
9.9 CRITICAL

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated …

Aug 5, 2026
CVE-2026-71289
9.8 CRITICAL

The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, …

Aug 5, 2026
CVE-2026-71278
9.8 CRITICAL

rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` field. This route does not take the AuthToken request guard used …

Aug 5, 2026
CVE-2026-71277
9.1 CRITICAL

rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or …

Aug 5, 2026
CVE-2026-71268
9.9 CRITICAL

OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) program files and writes the referenced content to `os.path.join('./core', file_path)` …

Aug 5, 2026
CVE-2026-71267
9.8 CRITICAL

microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no …

Aug 5, 2026
CVE-2026-71263
9.1 CRITICAL

The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesLeft > MB_TCP_BUF_SIZE)` uses a strict greater-than comparison instead …

Aug 5, 2026
CVE-2026-71262
9.8 CRITICAL

IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured …

Aug 5, 2026
CVE-2026-71256
9.8 CRITICAL

nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic() / recv_read_device_identification_res() in nanomodbus.c. A fixed 3-element stack array order[3] …

Aug 5, 2026
CVE-2026-71254
9.8 CRITICAL

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record() function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the …

Aug 5, 2026
CVE-2026-71248
9.8 CRITICAL

Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: $sql = "select * from user where email = '$email' and …

Aug 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.