CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-71238
9.1 CRITICAL

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for …

Aug 5, 2026
CVE-2026-71237
9.8 CRITICAL

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from $_POST['pwd'] with no sanitization and concatenates it into a raw SQL string: …

Aug 5, 2026
CVE-2026-71231
9.8 CRITICAL

IOTSmartHome's gui/login.php checkCookie() function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after base64-decoding the client-supplied lastLogin cookie via safe_decode(), …

Aug 5, 2026
CVE-2026-66747
9.8 CRITICAL

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built …

Aug 5, 2026
CVE-2026-44945
9.1 CRITICAL

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access …

Aug 5, 2026
CVE-2026-10090
9.9 CRITICAL

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges …

Aug 5, 2026
CVE-2026-10059
9.1 CRITICAL

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a …

Aug 5, 2026
CVE-2026-71214
9.8 CRITICAL

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON …

Aug 5, 2026
CVE-2026-71213
9.1 CRITICAL

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated …

Aug 5, 2026
CVE-2026-71207
9.8 CRITICAL

The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL …

Aug 5, 2026
CVE-2026-70376
9.6 CRITICAL

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain() in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token …

Aug 5, 2026
CVE-2026-61486
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we …

Aug 5, 2026
CVE-2026-61484
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, …

Aug 5, 2026
CVE-2026-5581
9.1 CRITICAL

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This …

Aug 5, 2026
CVE-2026-4431
9.1 CRITICAL

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in …

Aug 5, 2026
CVE-2026-15360
9.1 CRITICAL

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated …

Aug 5, 2026
CVE-2026-15210
9.1 CRITICAL

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate a one-time …

Aug 5, 2026
CVE-2026-9273
9.3 CRITICAL

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in all …

Aug 5, 2026
CVE-2026-45537
9.1 CRITICAL

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, …

Aug 4, 2026
CVE-2026-45100
9.1 CRITICAL

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The …

Aug 4, 2026
CVE-2026-70554
9.8 CRITICAL

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie …

Aug 4, 2026
CVE-2026-67979
9.1 CRITICAL

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a …

Aug 4, 2026
CVE-2026-66902
9.8 CRITICAL

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command …

Aug 4, 2026
CVE-2026-45538
9.8 CRITICAL

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 …

Aug 4, 2026
CVE-2026-70553
9.8 CRITICAL

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted …

Aug 4, 2026
CVE-2026-70552
9.8 CRITICAL

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any …

Aug 4, 2026
CVE-2026-69703
9.8 CRITICAL

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw …

Aug 4, 2026
CVE-2026-49435
9.8 CRITICAL

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code …

Aug 4, 2026
CVE-2026-0163
9.8 CRITICAL

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of …

Aug 4, 2026
CVE-2017-20242
9.8 CRITICAL

Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or …

Aug 4, 2026
CVE-2017-20241
9.8 CRITICAL

Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or …

Aug 4, 2026
CVE-2026-24254
9.8 CRITICAL

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this …

Aug 4, 2026
CVE-2026-63456
9.8 CRITICAL

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access …

Aug 4, 2026
CVE-2026-63455
9.8 CRITICAL

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access …

Aug 4, 2026
CVE-2025-29296
9.8 CRITICAL

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C …

Aug 4, 2026
CVE-2026-69110
9.1 CRITICAL

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by …

Aug 4, 2026
CVE-2026-69098
9.8 CRITICAL

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON …

Aug 4, 2026
CVE-2026-25289
9.6 CRITICAL

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

Aug 4, 2026
CVE-2026-61515
9.8 CRITICAL

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by …

Aug 4, 2026
CVE-2026-61514
9.8 CRITICAL

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets …

Aug 4, 2026
CVE-2026-15721
9.8 CRITICAL

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital …

Aug 4, 2026
CVE-2026-14804
9.1 CRITICAL

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This …

Aug 4, 2026
CVE-2026-14175
9.8 CRITICAL

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to …

Aug 4, 2026
CVE-2026-18754
9.1 CRITICAL

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows …

Aug 4, 2026
CVE-2026-18753
9.1 CRITICAL

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows …

Aug 4, 2026
CVE-2026-16618
9.8 CRITICAL

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the …

Aug 4, 2026
CVE-2026-15958
9.3 CRITICAL

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers …

Aug 4, 2026
CVE-2026-18686
9.8 CRITICAL

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web …

Aug 4, 2026
CVE-2026-18685
9.8 CRITICAL

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. …

Aug 4, 2026
CVE-2026-48333
9.8 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.