CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-67289
9.8 CRITICAL

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied …

Aug 1, 2026
CVE-2026-66402
9.8 CRITICAL

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name …

Aug 1, 2026
CVE-2026-15964
9.8 CRITICAL

The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, …

Aug 1, 2026
CVE-2026-13596
9.1 CRITICAL

The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated …

Aug 1, 2026
CVE-2026-3141
9.1 CRITICAL

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in …

Aug 1, 2026
CVE-2026-68771
9.8 CRITICAL

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted …

Jul 31, 2026
CVE-2026-52134
9.8 CRITICAL

An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.

Jul 31, 2026
CVE-2026-68770
9.8 CRITICAL

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within …

Jul 31, 2026
CVE-2026-51785
9.8 CRITICAL

An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request

Jul 31, 2026
CVE-2026-38713
9.8 CRITICAL

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command …

Jul 31, 2026
CVE-2026-38708
9.8 CRITICAL

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command …

Jul 31, 2026
CVE-2025-69948
9.8 CRITICAL

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.

Jul 31, 2026
CVE-2025-69946
9.8 CRITICAL

SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.

Jul 31, 2026
CVE-2026-38711
9.8 CRITICAL

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command …

Jul 31, 2026
CVE-2026-54725
9.6 CRITICAL

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap …

Jul 31, 2026
CVE-2026-67822
9.8 CRITICAL

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters …

Jul 31, 2026
CVE-2026-52855
9.9 CRITICAL

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow …

Jul 31, 2026
CVE-2026-17566
9.9 CRITICAL

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the …

Jul 31, 2026
CVE-2026-17351
9.0 CRITICAL

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly …

Jul 31, 2026
CVE-2026-17349
9.6 CRITICAL

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which …

Jul 31, 2026
CVE-2026-16504
9.8 CRITICAL

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

Jul 31, 2026
CVE-2026-16503
9.1 CRITICAL

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to …

Jul 31, 2026
CVE-2026-17561
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue …

Jul 31, 2026
CVE-2026-18452
10.0 CRITICAL

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control …

Jul 31, 2026
CVE-2026-14919
9.8 CRITICAL

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied …

Jul 31, 2026
CVE-2026-14483
9.8 CRITICAL

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, …

Jul 31, 2026
CVE-2026-63223
9.8 CRITICAL

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename …

Jul 31, 2026
CVE-2026-63221
9.4 CRITICAL

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring …

Jul 31, 2026
CVE-2026-43830
9.8 CRITICAL

Full details and mitigation steps are currently restricted and will be published at a later date.

Jul 31, 2026
CVE-2026-66421
9.3 CRITICAL

OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML …

Jul 30, 2026
CVE-2026-38709
9.8 CRITICAL

TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command …

Jul 30, 2026
CVE-2026-68503
9.8 CRITICAL

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and …

Jul 30, 2026
CVE-2026-68502
9.8 CRITICAL

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches …

Jul 30, 2026
CVE-2026-66803
10.0 CRITICAL

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

Jul 30, 2026
CVE-2026-66418
9.3 CRITICAL

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted …

Jul 30, 2026
CVE-2026-52539
9.1 CRITICAL

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default …

Jul 30, 2026
CVE-2026-35847
9.8 CRITICAL

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

Jul 30, 2026
CVE-2025-69947
9.8 CRITICAL

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

Jul 30, 2026
CVE-2025-69941
9.8 CRITICAL

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

Jul 30, 2026
CVE-2025-69938
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

Jul 30, 2026
CVE-2025-69937
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

Jul 30, 2026
CVE-2025-69936
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

Jul 30, 2026
CVE-2025-69935
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

Jul 30, 2026
CVE-2025-69934
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

Jul 30, 2026
CVE-2025-69933
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

Jul 30, 2026
CVE-2025-69931
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

Jul 30, 2026
CVE-2025-69930
9.8 CRITICAL

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

Jul 30, 2026
CVE-2025-65336
9.8 CRITICAL

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

Jul 30, 2026
CVE-2026-67594
9.8 CRITICAL

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, …

Jul 30, 2026
CVE-2026-67208
9.8 CRITICAL

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 …

Jul 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.