CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14529
9.4 CRITICAL

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) …

Jul 29, 2026
CVE-2026-41939
9.8 CRITICAL

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access …

Jul 29, 2026
CVE-2026-54680
9.9 CRITICAL

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such …

Jul 29, 2026
CVE-2026-51992
9.1 CRITICAL

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.

Jul 29, 2026
CVE-2026-67191
9.8 CRITICAL

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap …

Jul 29, 2026
CVE-2026-60113
9.8 CRITICAL

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager that …

Jul 29, 2026
CVE-2026-60112
9.8 CRITICAL

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue …

Jul 29, 2026
CVE-2026-54735
10.0 CRITICAL

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate …

Jul 29, 2026
CVE-2026-14900
9.8 CRITICAL

The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php …

Jul 29, 2026
CVE-2026-14488
9.1 CRITICAL

The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up …

Jul 29, 2026
CVE-2026-59243
9.8 CRITICAL

The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned …

Jul 29, 2026
CVE-2026-58162
10.0 CRITICAL

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 …

Jul 29, 2026
CVE-2025-10656
9.8 CRITICAL

The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and …

Jul 29, 2026
CVE-2026-58155
9.3 CRITICAL

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, …

Jul 29, 2026
CVE-2026-58150
10.0 CRITICAL

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from …

Jul 29, 2026
CVE-2026-57834
10.0 CRITICAL

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, …

Jul 29, 2026
CVE-2026-41920
9.3 CRITICAL

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended …

Jul 29, 2026
CVE-2026-33267
10.0 CRITICAL

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended …

Jul 29, 2026
CVE-2026-18191
9.8 CRITICAL

VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden function to obtain the administrator credentials of …

Jul 29, 2026
CVE-2026-63234
9.9 CRITICAL

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessment endpoint, control data passed …

Jul 29, 2026
CVE-2026-63233
9.9 CRITICAL

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall answer endpoint, control data passed …

Jul 29, 2026
CVE-2026-63232
9.9 CRITICAL

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcement endpoint, control data passed to …

Jul 29, 2026
CVE-2026-63230
9.1 CRITICAL

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, including personally identifiable information, credentials, and valid …

Jul 29, 2026
CVE-2026-63229
9.1 CRITICAL

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO OAuth endpoint to …

Jul 29, 2026
CVE-2026-63227
9.9 CRITICAL

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a …

Jul 29, 2026
CVE-2026-13423
9.8 CRITICAL

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which invokes an attacker-supplied …

Jul 29, 2026
CVE-2026-18072
9.8 CRITICAL

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in …

Jul 29, 2026
CVE-2026-64863
9.1 CRITICAL

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method …

Jul 28, 2026
CVE-2026-62325
9.1 CRITICAL

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && …

Jul 28, 2026
CVE-2026-54658
9.8 CRITICAL

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing …

Jul 28, 2026
CVE-2026-14973
9.3 CRITICAL

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Jul 28, 2026
CVE-2026-14959
9.1 CRITICAL

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to shell command injection.

Jul 28, 2026
CVE-2026-14958
9.1 CRITICAL

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation.

Jul 28, 2026
CVE-2026-14512
9.8 CRITICAL

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute …

Jul 28, 2026
CVE-2026-14446
9.8 CRITICAL

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Jul 28, 2026
CVE-2026-16498
10.0 CRITICAL

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform …

Jul 28, 2026
CVE-2026-66713
9.8 CRITICAL

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering …

Jul 28, 2026
CVE-2026-16462
9.8 CRITICAL

In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.

Jul 28, 2026
CVE-2026-11841
9.4 CRITICAL

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A …

Jul 28, 2026
CVE-2026-15014
9.8 CRITICAL

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to Authentication Bypass leading to …

Jul 28, 2026
CVE-2026-11756
10.0 CRITICAL

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an …

Jul 28, 2026
CVE-2026-14545
9.8 CRITICAL

The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its front-end account handlers, allowing unauthenticated …

Jul 28, 2026
CVE-2021-32088
9.8 CRITICAL

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This …

Jul 27, 2026
CVE-2021-32086
9.8 CRITICAL

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL …

Jul 27, 2026
CVE-2021-32084
9.8 CRITICAL

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or …

Jul 27, 2026
CVE-2026-64775
9.8 CRITICAL

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma …

Jul 27, 2026
CVE-2026-64774
9.8 CRITICAL

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, …

Jul 27, 2026
CVE-2026-64772
9.8 CRITICAL

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe …

Jul 27, 2026
CVE-2026-64771
9.8 CRITICAL

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, …

Jul 27, 2026
CVE-2026-64770
9.8 CRITICAL

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma …

Jul 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.