CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76761
7.3 HIGH

A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the component Management API. Such …

Aug 19, 2026
CVE-2026-76760
7.3 HIGH

A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of …

Aug 19, 2026
CVE-2026-19563

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 19, 2026
CVE-2026-19562

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 19, 2026
CVE-2026-19561

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 19, 2026
CVE-2026-18862

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 19, 2026
CVE-2026-18502

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 19, 2026
CVE-2026-76878

In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for …

Aug 19, 2026
CVE-2026-76850
9.8 CRITICAL

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), …

Aug 19, 2026
CVE-2026-76832
8.8 HIGH

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in …

Aug 19, 2026
CVE-2026-76591
7.4 HIGH

A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. …

Aug 19, 2026
CVE-2026-76590
9.9 CRITICAL

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component …

Aug 19, 2026
CVE-2026-76589
9.9 CRITICAL

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid …

Aug 19, 2026
CVE-2026-76405
4.3 MEDIUM

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a …

Aug 19, 2026
CVE-2026-76404
9.1 CRITICAL

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. …

Aug 19, 2026
CVE-2026-76403
7.4 HIGH

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from …

Aug 19, 2026
CVE-2026-76402
8.2 HIGH

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a …

Aug 19, 2026
CVE-2026-76401
5.9 MEDIUM

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp …

Aug 19, 2026
CVE-2026-76400
5.9 MEDIUM

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses …

Aug 19, 2026
CVE-2026-76399
8.1 HIGH

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing …

Aug 19, 2026
CVE-2026-76398
4.3 MEDIUM

In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of …

Aug 19, 2026
CVE-2026-76397
8.1 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, …

Aug 19, 2026
CVE-2026-76396
7.5 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and …

Aug 19, 2026
CVE-2026-76395
8.8 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading …

Aug 19, 2026
CVE-2026-76394
8.3 HIGH

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure …

Aug 19, 2026
CVE-2026-76393
5.9 MEDIUM

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a …

Aug 19, 2026
CVE-2026-76392
5.4 MEDIUM

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials …

Aug 19, 2026
CVE-2026-76391
8.3 HIGH

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, …

Aug 19, 2026
CVE-2026-76390
5.3 MEDIUM

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file …

Aug 19, 2026
CVE-2026-76389
8.8 HIGH

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted …

Aug 19, 2026
CVE-2026-76388
8.1 HIGH

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) …

Aug 19, 2026
CVE-2026-76387
8.1 HIGH

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing …

Aug 19, 2026
CVE-2026-76386
4.3 MEDIUM

In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting …

Aug 19, 2026
CVE-2026-76385
4.3 MEDIUM

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore …

Aug 19, 2026
CVE-2026-76384
4.3 MEDIUM

In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could …

Aug 19, 2026
CVE-2026-76383
4.3 MEDIUM

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions …

Aug 19, 2026
CVE-2026-76382
4.3 MEDIUM

In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a …

Aug 19, 2026
CVE-2026-76381
4.3 MEDIUM

In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run …

Aug 19, 2026
CVE-2026-76380
4.3 MEDIUM

In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could …

Aug 19, 2026
CVE-2026-76379
4.3 MEDIUM

In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose …

Aug 19, 2026
CVE-2026-76378
4.3 MEDIUM

In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions …

Aug 19, 2026
CVE-2026-76377
4.3 MEDIUM

In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could …

Aug 19, 2026
CVE-2026-76376
4.3 MEDIUM

In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose …

Aug 19, 2026
CVE-2026-76375
5.0 MEDIUM

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose …

Aug 19, 2026
CVE-2026-76374
4.3 MEDIUM

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause …

Aug 19, 2026
CVE-2026-76373
5.4 MEDIUM

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject …

Aug 19, 2026
CVE-2026-76372
6.6 MEDIUM

In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the …

Aug 19, 2026
CVE-2026-76371
2.7 LOW

In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add …

Aug 19, 2026
CVE-2026-76370
4.3 MEDIUM

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names …

Aug 19, 2026
CVE-2026-76369
2.7 LOW

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The …

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.