CVE Database

133011+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-74803

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls …

Aug 19, 2026
CVE-2026-71694
8.8 HIGH

An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile RTL benchmark v1.2 2d08d0d8b4563212175212f9db0e69f6e68c9619 allows a remote attacker to execute arbitrary code via the CSR trap-return …

Aug 19, 2026
CVE-2026-70424
6.5 MEDIUM

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker …

Aug 19, 2026
CVE-2026-70423
6.5 MEDIUM

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could …

Aug 19, 2026
CVE-2026-70422
8.1 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged …

Aug 19, 2026
CVE-2026-70421
7.2 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, …

Aug 19, 2026
CVE-2026-65612

nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside …

Aug 19, 2026
CVE-2026-65611

nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive whose …

Aug 19, 2026
CVE-2026-65610

nnn stores homelen variable as uchar_t, which can only represent values in the range 0-255. An attacker who can influence the victim's execution environment can …

Aug 19, 2026
CVE-2026-65609

nnn is vulnerable to Out-of-Bound write vulnerability. Due to lack of validation of attacker-controlled length fields deserialized from a session file, a crafted session file …

Aug 19, 2026
CVE-2026-56088
7.1 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged …

Aug 19, 2026
CVE-2026-54796
7.2 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high …

Aug 19, 2026
CVE-2026-54795
8.8 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 19, 2026
CVE-2026-54794
7.2 HIGH

Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, …

Aug 19, 2026
CVE-2026-51367
7.5 HIGH

An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter

Aug 19, 2026
CVE-2026-51366
9.9 CRITICAL

SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter

Aug 19, 2026
CVE-2026-50720
6.4 MEDIUM

The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word …

Aug 19, 2026
CVE-2026-50719
6.8 MEDIUM

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before …

Aug 19, 2026
CVE-2026-43961
7.8 HIGH

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during …

Aug 19, 2026
CVE-2026-16019
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects …

Aug 19, 2026
CVE-2024-58376
8.8 HIGH

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary …

Aug 19, 2026
CVE-2020-37267
7.5 HIGH

Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION …

Aug 19, 2026
CVE-2019-25766
7.5 HIGH

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is …

Aug 19, 2026
CVE-2026-76235
7.5 HIGH

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, …

Aug 19, 2026
CVE-2026-73394
7.5 HIGH

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.

Aug 19, 2026
CVE-2026-73391
9.3 CRITICAL

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

Aug 19, 2026
CVE-2026-73390
9.8 CRITICAL

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

Aug 19, 2026
CVE-2026-73389
9.8 CRITICAL

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

Aug 19, 2026
CVE-2026-73388
9.3 CRITICAL

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

Aug 19, 2026
CVE-2026-73387
8.1 HIGH

Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

Aug 19, 2026
CVE-2026-73386
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.

Aug 19, 2026
CVE-2026-73385
7.5 HIGH

Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.

Aug 19, 2026
CVE-2026-73384
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

Aug 19, 2026
CVE-2026-73364
9.8 CRITICAL

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

Aug 19, 2026
CVE-2026-73363
6.5 MEDIUM

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.

Aug 19, 2026
CVE-2026-73354
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.

Aug 19, 2026
CVE-2026-73347
9.8 CRITICAL

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

Aug 19, 2026
CVE-2026-73185
9.3 CRITICAL

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

Aug 19, 2026
CVE-2026-73184
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.

Aug 19, 2026
CVE-2026-73183
9.3 CRITICAL

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

Aug 19, 2026
CVE-2026-73182
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.

Aug 19, 2026
CVE-2026-67364

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The …

Aug 19, 2026
CVE-2026-67363

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from …

Aug 19, 2026
CVE-2026-66668
8.5 HIGH

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

Aug 19, 2026
CVE-2026-66613
9.8 CRITICAL

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

Aug 19, 2026
CVE-2026-66596
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.

Aug 19, 2026
CVE-2026-61986
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.

Aug 19, 2026
CVE-2026-32552
8.5 HIGH

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

Aug 19, 2026
CVE-2026-19490
KEV

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 …

Aug 19, 2026
CVE-2026-19489

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 …

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.