CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-75910
6.5 MEDIUM

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read …

Aug 20, 2026
CVE-2026-72861
5.8 MEDIUM

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' …

Aug 20, 2026
CVE-2026-63723

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-9033

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of …

Aug 20, 2026
CVE-2026-8717

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-77148
9.9 CRITICAL

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results …

Aug 20, 2026
CVE-2026-75526
4.4 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled …

Aug 20, 2026
CVE-2026-75514
5.9 MEDIUM

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix …

Aug 20, 2026
CVE-2026-72854
5.3 MEDIUM

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the …

Aug 20, 2026
CVE-2026-72852
7.8 HIGH

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In …

Aug 20, 2026
CVE-2026-6822

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-6260

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-66788
9.9 CRITICAL

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection …

Aug 20, 2026
CVE-2026-66787
8.7 HIGH

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP …

Aug 20, 2026
CVE-2026-66785
9.9 CRITICAL

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing …

Aug 20, 2026
CVE-2026-66002

Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response …

Aug 20, 2026
CVE-2026-66001

Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to …

Aug 20, 2026
CVE-2026-64777
4.3 MEDIUM

A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name …

Aug 20, 2026
CVE-2026-63654

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow …

Aug 20, 2026
CVE-2026-63003
6.5 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on …

Aug 20, 2026
CVE-2026-62315

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden …

Aug 20, 2026
CVE-2026-61663
4.3 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use …

Aug 20, 2026
CVE-2026-54624
6.5 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent …

Aug 20, 2026
CVE-2026-54622
6.5 MEDIUM

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the …

Aug 20, 2026
CVE-2026-53993

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-53587
7.5 HIGH

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53586
6.5 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53585
5.3 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53584
4.3 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53583
6.5 MEDIUM

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Aug 20, 2026
CVE-2026-53569

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce …

Aug 20, 2026
CVE-2026-50190

Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into …

Aug 20, 2026
CVE-2026-49996
3.7 LOW

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a …

Aug 20, 2026
CVE-2026-46537

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-46536

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-46535

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-46534

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-46533

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 20, 2026
CVE-2026-43678
5.3 MEDIUM

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping …

Aug 20, 2026
CVE-2026-19683

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over …

Aug 20, 2026
CVE-2026-19586

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied …

Aug 20, 2026
CVE-2026-15743

Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of …

Aug 20, 2026
CVE-2026-77036
6.3 MEDIUM

A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack …

Aug 20, 2026
CVE-2026-77031
7.4 HIGH

A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument …

Aug 20, 2026
CVE-2026-76641
7.5 HIGH

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external entity parsers created via XML_ExternalEntityParserCreate. …

Aug 20, 2026
CVE-2026-73259
5.4 MEDIUM

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deployment …

Aug 20, 2026
CVE-2026-73258
6.5 MEDIUM

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in …

Aug 20, 2026
CVE-2026-73257
9.1 CRITICAL

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length …

Aug 20, 2026
CVE-2026-73256
9.1 CRITICAL

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a …

Aug 20, 2026
CVE-2026-73255
6.5 MEDIUM

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal sequences …

Aug 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.