CVE Database

45033+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-88024
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88023
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88022
7.7 HIGH

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter …

Sep 10, 2026
CVE-2026-88048
7.1 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ …

Sep 10, 2026
CVE-2026-88047
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses …

Sep 10, 2026
CVE-2026-88045
7.5 HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed …

Sep 10, 2026
CVE-2026-73699
7.2 HIGH

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in …

Sep 10, 2026
CVE-2026-73698
7.2 HIGH

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an …

Sep 10, 2026
CVE-2026-73694
7.2 HIGH

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input …

Sep 10, 2026
CVE-2026-73693
8.8 HIGH

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by …

Sep 10, 2026
CVE-2026-88959
8.8 HIGH

Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify …

Sep 10, 2026
CVE-2026-88939
8.3 HIGH

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint …

Sep 10, 2026
CVE-2026-88937
8.8 HIGH

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside …

Sep 10, 2026
CVE-2026-88017
7.3 HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver …

Sep 10, 2026
CVE-2026-88016
7.1 HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, …

Sep 10, 2026
CVE-2026-88011
8.1 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as …

Sep 10, 2026
CVE-2026-88009
8.2 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go …

Sep 10, 2026
CVE-2026-79987
8.8 HIGH

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Sep 10, 2026
CVE-2026-4130
7.1 HIGH

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive …

Sep 10, 2026
CVE-2026-4129
8.1 HIGH

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files …

Sep 10, 2026
CVE-2026-88924
7.0 HIGH

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling …

Sep 10, 2026
CVE-2026-88004
7.4 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but …

Sep 10, 2026
CVE-2026-84821
7.5 HIGH

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

Sep 10, 2026
CVE-2026-84819
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.

Sep 10, 2026
CVE-2026-84816
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.

Sep 10, 2026
CVE-2026-81805
8.1 HIGH

Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

Sep 10, 2026
CVE-2026-81804
7.5 HIGH

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

Sep 10, 2026
CVE-2026-81803
7.5 HIGH

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

Sep 10, 2026
CVE-2026-81801
8.1 HIGH

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

Sep 10, 2026
CVE-2026-81799
7.5 HIGH

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

Sep 10, 2026
CVE-2026-81796
7.3 HIGH

Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.

Sep 10, 2026
CVE-2026-81795
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.

Sep 10, 2026
CVE-2026-81794
7.5 HIGH

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

Sep 10, 2026
CVE-2026-81789
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This …

Sep 10, 2026
CVE-2026-81786
7.5 HIGH

Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions.

Sep 10, 2026
CVE-2026-81784
8.1 HIGH

Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.

Sep 10, 2026
CVE-2026-81783
7.1 HIGH

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

Sep 10, 2026
CVE-2026-46387
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path …

Sep 10, 2026
CVE-2026-45747
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper …

Sep 10, 2026
CVE-2026-88895
7.2 HIGH

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's …

Sep 10, 2026
CVE-2026-88893
7.5 HIGH

OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link …

Sep 10, 2026
CVE-2026-88891
8.3 HIGH

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers …

Sep 10, 2026
CVE-2026-88890
8.5 HIGH

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them …

Sep 10, 2026
CVE-2026-88889
7.8 HIGH

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType …

Sep 10, 2026
CVE-2026-88888
7.0 HIGH

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters …

Sep 10, 2026
CVE-2026-88887
8.6 HIGH

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the …

Sep 10, 2026
CVE-2026-88886
7.8 HIGH

Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before …

Sep 10, 2026
CVE-2026-88885
7.0 HIGH

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers …

Sep 10, 2026
CVE-2026-88883
7.7 HIGH

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), …

Sep 10, 2026
CVE-2026-88882
8.6 HIGH

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.