CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14163

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable snapshot in clear-text.

Aug 20, 2026
CVE-2025-14602

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to accurately guess …

Aug 20, 2026
CVE-2026-75963
7.5 HIGH

The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_page_template function. …

Aug 20, 2026
CVE-2026-75860
9.8 CRITICAL

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every …

Aug 20, 2026
CVE-2026-74992
6.8 MEDIUM

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not …

Aug 20, 2026
CVE-2026-73542
3.7 LOW

Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. …

Aug 20, 2026
CVE-2026-19699
2.7 LOW

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor …

Aug 20, 2026
CVE-2026-19697
6.8 MEDIUM

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file …

Aug 20, 2026
CVE-2026-19615
6.8 MEDIUM

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users …

Aug 20, 2026
CVE-2026-17153
5.3 MEDIUM

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to …

Aug 20, 2026
CVE-2026-15049
7.2 HIGH

The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and …

Aug 20, 2026
CVE-2026-13405
6.6 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later …

Aug 20, 2026
CVE-2026-76957
4.9 MEDIUM

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and …

Aug 20, 2026
CVE-2026-76956
5.9 MEDIUM

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, …

Aug 20, 2026
CVE-2026-19582
0.0 NONE

In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buffer …

Aug 20, 2026
CVE-2026-76800
6.3 MEDIUM

A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the …

Aug 20, 2026
CVE-2026-76799
5.3 MEDIUM

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database …

Aug 20, 2026
CVE-2026-76795
7.3 HIGH

A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. The …

Aug 20, 2026
CVE-2026-76785
6.3 MEDIUM

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument …

Aug 20, 2026
CVE-2026-76783
7.3 HIGH

A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such manipulation of the argument sql leads …

Aug 20, 2026
CVE-2026-75628

Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path accepts a backslash or tab in the return parameter. oauth2_login …

Aug 20, 2026
CVE-2026-8619

An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request …

Aug 20, 2026
CVE-2026-76764
7.3 HIGH

A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component …

Aug 20, 2026
CVE-2026-76762
7.3 HIGH

A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument …

Aug 20, 2026
CVE-2022-4996
5.3 MEDIUM

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point …

Aug 20, 2026
CVE-2026-76929
4.7 MEDIUM

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76928
7.5 HIGH

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76927
4.7 MEDIUM

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76926
3.1 LOW

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76924
5.5 MEDIUM

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76923
5.5 MEDIUM

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76922
5.5 MEDIUM

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76921
5.5 MEDIUM

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76920
4.7 MEDIUM

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76919
5.3 MEDIUM

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76918
5.5 MEDIUM

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76917
5.5 MEDIUM

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76891
3.1 LOW

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76890
3.1 LOW

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76889
4.7 MEDIUM

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76888
3.1 LOW

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76887
3.1 LOW

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76886
8.1 HIGH

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76885
3.1 LOW

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76884
3.1 LOW

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76883
4.7 MEDIUM

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76882
4.7 MEDIUM

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76881
4.7 MEDIUM

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76880
7.5 HIGH

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76879
7.5 HIGH

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.