CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-74594
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sched/psi: Shut down rtpoll_timer in psi_cgroup_free() psi_schedule_rtpoll_work() is called locklessly from the scheduler hotpath and …

Aug 22, 2026
CVE-2026-74593

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Take cgroup_lock() first in scx_cgroup_lock() scx_cgroup_lock() write-locks scx_cgroup_ops_rwsem and then takes cgroup_lock(), which can …

Aug 22, 2026
CVE-2026-74592
8.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ima: Instantiate file_truncate and path_truncate hooks Instantiate the file_truncate and path_truncate LSM hooks to reset …

Aug 22, 2026
CVE-2026-74591
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index before retrying In __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is applied repeatedly: each …

Aug 22, 2026
CVE-2026-74590
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions The BPF verifier and the dynptr abstraction ensure that the …

Aug 22, 2026
CVE-2026-74589
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix sk_redir use-after-free in send verdict sk_psock_msg_verdict() takes a socket reference for psock->sk_redir. …

Aug 22, 2026
CVE-2026-74588
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list it is queued on __sctp_outq_flush_rtx() moves a …

Aug 22, 2026
CVE-2026-74587
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk addip_last_asconf caches the outstanding outbound ASCONF chunk. The …

Aug 22, 2026
CVE-2026-74586
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in …

Aug 22, 2026
CVE-2026-74585

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound the DROM dual link port number before indexing sw->ports tb_drom_parse_entry_port() validates the device-supplied …

Aug 22, 2026
CVE-2026-4703
9.8 CRITICAL

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, …

Aug 22, 2026
CVE-2026-77992

Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access …

Aug 22, 2026
CVE-2026-77027

Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to …

Aug 22, 2026
CVE-2026-76609

Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

Aug 22, 2026
CVE-2026-76608

Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not perform any access …

Aug 22, 2026
CVE-2026-76607

Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.

Aug 22, 2026
CVE-2026-76606

Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.

Aug 22, 2026
CVE-2026-76605

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

Aug 22, 2026
CVE-2026-76604

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to …

Aug 22, 2026
CVE-2026-76603

Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perform any access checks, …

Aug 22, 2026
CVE-2026-76602

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in …

Aug 22, 2026
CVE-2026-76601

Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks.

Aug 22, 2026
CVE-2026-76600

Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access checks.

Aug 22, 2026
CVE-2026-76599

Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the elements model allows …

Aug 22, 2026
CVE-2026-76598

Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method of the elements model allows arbitrary …

Aug 22, 2026
CVE-2026-76597

Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin …

Aug 22, 2026
CVE-2026-76596

Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks ACL gates, a plain GET …

Aug 22, 2026
CVE-2026-76571

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list …

Aug 22, 2026
CVE-2026-74584
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to userspace bnxt_re_alloc_ucontext() allocates uctx->shpg via __get_free_page(GFP_KERNEL). The buddy …

Aug 22, 2026
CVE-2026-70626
6.2 MEDIUM

NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability …

Aug 22, 2026
CVE-2026-6258

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 22, 2026
CVE-2026-68768
6.1 MEDIUM

hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the …

Aug 22, 2026
CVE-2026-68767
6.1 MEDIUM

hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers …

Aug 22, 2026
CVE-2026-68766
7.8 HIGH

hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files …

Aug 22, 2026
CVE-2026-66393
7.5 HIGH

NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. …

Aug 22, 2026
CVE-2026-65915
6.5 MEDIUM

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check …

Aug 22, 2026
CVE-2026-63312
7.5 HIGH

NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control …

Aug 22, 2026
CVE-2026-63311
5.3 MEDIUM

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError …

Aug 22, 2026
CVE-2026-63310
7.1 HIGH

NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS …

Aug 22, 2026
CVE-2026-62388
7.5 HIGH

NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path …

Aug 22, 2026
CVE-2026-62385
5.9 MEDIUM

NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by …

Aug 22, 2026
CVE-2026-62384
7.5 HIGH

NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can …

Aug 22, 2026
CVE-2026-62383
5.5 MEDIUM

nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in …

Aug 22, 2026
CVE-2026-75870
9.1 CRITICAL

Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The …

Aug 22, 2026
CVE-2026-75866
9.1 CRITICAL

Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers …

Aug 22, 2026
CVE-2026-71514
2.5 LOW

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus …

Aug 22, 2026
CVE-2026-71513
8.8 HIGH

NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers …

Aug 22, 2026
CVE-2026-68769

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 22, 2026
CVE-2026-5093
4.3 MEDIUM

The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. …

Aug 22, 2026
CVE-2026-4561
6.4 MEDIUM

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') …

Aug 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.