CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-21751
7.4 HIGH

HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if …

Aug 24, 2026
CVE-2026-17033
6.8 MEDIUM

An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the …

Aug 24, 2026
CVE-2025-68833
5.3 MEDIUM

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.

Aug 24, 2026
CVE-2026-78365

Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify …

Aug 24, 2026
CVE-2026-78247
7.3 HIGH

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of …

Aug 24, 2026
CVE-2026-21759
4.3 MEDIUM

HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, …

Aug 24, 2026
CVE-2026-21756
7.2 HIGH

HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code …

Aug 24, 2026
CVE-2026-78323
6.5 MEDIUM

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present …

Aug 24, 2026
CVE-2026-78291
5.3 MEDIUM

Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

Aug 24, 2026
CVE-2026-78290
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

Aug 24, 2026
CVE-2026-78280
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Hash Form <= 1.4.0 versions.

Aug 24, 2026
CVE-2026-78279
5.4 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.

Aug 24, 2026
CVE-2026-78278
5.3 MEDIUM

Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

Aug 24, 2026
CVE-2026-78277
4.9 MEDIUM

Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.

Aug 24, 2026
CVE-2026-78272
5.4 MEDIUM

Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.

Aug 24, 2026
CVE-2026-78270
7.6 HIGH

Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.

Aug 24, 2026
CVE-2026-78269
6.4 MEDIUM

Contributor Server Side Request Forgery (SSRF) in Shared Files <= 1.7.69 versions.

Aug 24, 2026
CVE-2026-78258
5.3 MEDIUM

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

Aug 24, 2026
CVE-2026-78246
7.3 HIGH

A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin …

Aug 24, 2026
CVE-2026-6017

Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sensitive information such as a password to …

Aug 24, 2026
CVE-2026-66671
8.1 HIGH

Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

Aug 24, 2026
CVE-2026-66670
8.1 HIGH

Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

Aug 24, 2026
CVE-2026-66650
9.8 CRITICAL

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

Aug 24, 2026
CVE-2026-66648
9.8 CRITICAL

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

Aug 24, 2026
CVE-2026-66623
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.

Aug 24, 2026
CVE-2026-66610
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.

Aug 24, 2026
CVE-2026-66599
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.

Aug 24, 2026
CVE-2026-66587
9.8 CRITICAL

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Aug 24, 2026
CVE-2026-66585
7.5 HIGH

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

Aug 24, 2026
CVE-2026-66584
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.

Aug 24, 2026
CVE-2026-32558
9.8 CRITICAL

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

Aug 24, 2026
CVE-2026-32551
9.3 CRITICAL

Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.

Aug 24, 2026
CVE-2026-32478
8.5 HIGH

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

Aug 24, 2026
CVE-2026-32477
8.6 HIGH

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

Aug 24, 2026
CVE-2026-32476
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.

Aug 24, 2026
CVE-2026-32471
8.5 HIGH

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

Aug 24, 2026
CVE-2026-28190
7.1 HIGH

Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.

Aug 24, 2026
CVE-2026-28171
8.6 HIGH

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

Aug 24, 2026
CVE-2026-28167
7.5 HIGH

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

Aug 24, 2026
CVE-2026-28166
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

Aug 24, 2026
CVE-2026-28165
9.8 CRITICAL

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

Aug 24, 2026
CVE-2026-28162
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

Aug 24, 2026
CVE-2026-28153
7.5 HIGH

Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.

Aug 24, 2026
CVE-2026-28152
8.1 HIGH

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

Aug 24, 2026
CVE-2026-28151
8.1 HIGH

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

Aug 24, 2026
CVE-2025-63080

Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform operations not possible via GUI, e.g. system …

Aug 24, 2026
CVE-2026-78337

Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the …

Aug 24, 2026
CVE-2026-78245
7.3 HIGH

A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. …

Aug 24, 2026
CVE-2026-78244
7.3 HIGH

A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a …

Aug 24, 2026
CVE-2026-76172
7.5 HIGH

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.