CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-66609
9.3 CRITICAL

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

Aug 20, 2026
CVE-2026-66607
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.

Aug 20, 2026
CVE-2026-66606
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.

Aug 20, 2026
CVE-2026-66605
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.

Aug 20, 2026
CVE-2026-66604
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in GeoDirectory <= 2.8.173 versions.

Aug 20, 2026
CVE-2026-66601
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.

Aug 20, 2026
CVE-2026-66600
9.1 CRITICAL

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

Aug 20, 2026
CVE-2026-66598
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in B2BKing Premium <= 5.6.07 versions.

Aug 20, 2026
CVE-2026-66597
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.4 versions.

Aug 20, 2026
CVE-2026-66595
5.9 MEDIUM

Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

Aug 20, 2026
CVE-2026-66594
8.5 HIGH

Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

Aug 20, 2026
CVE-2026-66593
9.3 CRITICAL

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

Aug 20, 2026
CVE-2026-66592
9.3 CRITICAL

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

Aug 20, 2026
CVE-2026-66590
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions.

Aug 20, 2026
CVE-2026-66586
6.6 MEDIUM

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Aug 20, 2026
CVE-2026-66583
9.8 CRITICAL

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

Aug 20, 2026
CVE-2026-66582
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions.

Aug 20, 2026
CVE-2026-66581
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.

Aug 20, 2026
CVE-2026-28150
8.1 HIGH

Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions.

Aug 20, 2026
CVE-2025-62307
5.4 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.

Aug 20, 2026
CVE-2025-53999
6.5 MEDIUM

Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.

Aug 20, 2026
CVE-2025-15689
9.8 CRITICAL

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

Aug 20, 2026
CVE-2025-15688
9.3 CRITICAL

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

Aug 20, 2026
CVE-2025-15637
8.1 HIGH

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

Aug 20, 2026
CVE-2026-77067
5.0 MEDIUM

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook …

Aug 20, 2026
CVE-2026-77066
5.0 MEDIUM

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), …

Aug 20, 2026
CVE-2026-77026

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An …

Aug 20, 2026
CVE-2026-73199
6.5 MEDIUM

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight …

Aug 20, 2026
CVE-2026-73198
7.5 HIGH

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. …

Aug 20, 2026
CVE-2026-73197
7.5 HIGH

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This …

Aug 20, 2026
CVE-2026-73196
4.3 MEDIUM

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized …

Aug 20, 2026
CVE-2026-13097
9.1 CRITICAL

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly …

Aug 20, 2026
CVE-2026-11861
9.6 CRITICAL

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA …

Aug 20, 2026
CVE-2026-18917
7.8 HIGH

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted …

Aug 20, 2026
CVE-2026-77014
5.3 MEDIUM

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping …

Aug 20, 2026
CVE-2026-76610

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by …

Aug 20, 2026
CVE-2026-14953
4.3 MEDIUM

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

Aug 20, 2026
CVE-2026-14952
7.5 HIGH

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, …

Aug 20, 2026
CVE-2026-14951
8.0 HIGH

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

Aug 20, 2026
CVE-2026-14950
9.8 CRITICAL

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases …

Aug 20, 2026
CVE-2026-14949
6.5 MEDIUM

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts …

Aug 20, 2026
CVE-2026-14948
8.8 HIGH

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for …

Aug 20, 2026
CVE-2026-14947
7.2 HIGH

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files …

Aug 20, 2026
CVE-2026-14946
7.2 HIGH

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code execution due to improper …

Aug 20, 2026
CVE-2026-76569

Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

Aug 20, 2026
CVE-2026-76565

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

Aug 20, 2026
CVE-2026-76564

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

Aug 20, 2026
CVE-2026-75948

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and `file` …

Aug 20, 2026
CVE-2025-14601

An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system commands due to insufficient input filtering. …

Aug 20, 2026
CVE-2026-71368
6.1 MEDIUM

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

Aug 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.