CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-64813
10.0 CRITICAL

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Jul 23, 2026
CVE-2026-64812
10.0 CRITICAL

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Jul 23, 2026
CVE-2026-61951
9.8 CRITICAL

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

Jul 23, 2026
CVE-2026-61950
9.3 CRITICAL

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

Jul 23, 2026
CVE-2026-61949
9.3 CRITICAL

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

Jul 23, 2026
CVE-2026-61948
9.3 CRITICAL

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

Jul 23, 2026
CVE-2026-59555
10.0 CRITICAL

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

Jul 23, 2026
CVE-2026-59544
9.8 CRITICAL

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

Jul 23, 2026
CVE-2026-59543
9.9 CRITICAL

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

Jul 23, 2026
CVE-2026-59540
9.8 CRITICAL

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

Jul 23, 2026
CVE-2026-59526
9.3 CRITICAL

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Jul 23, 2026
CVE-2026-59525
9.3 CRITICAL

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

Jul 23, 2026
CVE-2026-59514
9.3 CRITICAL

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

Jul 23, 2026
CVE-2026-57784
9.6 CRITICAL

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Jul 23, 2026
CVE-2026-27064
9.1 CRITICAL

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

Jul 23, 2026
CVE-2026-65431
9.8 CRITICAL

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe …

Jul 23, 2026
CVE-2026-64874
9.8 CRITICAL

Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

Jul 23, 2026
CVE-2026-64873
9.8 CRITICAL

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

Jul 23, 2026
CVE-2026-15015
9.8 CRITICAL

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is …

Jul 23, 2026
CVE-2026-15011
9.8 CRITICAL

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and …

Jul 23, 2026
CVE-2026-14282
9.8 CRITICAL

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary …

Jul 23, 2026
CVE-2026-16723
9.0 CRITICAL

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement …

Jul 23, 2026
CVE-2026-60372
9.8 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60369
9.9 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60367
9.8 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60366
10.0 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-64798
9.1 CRITICAL

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random …

Jul 22, 2026
CVE-2026-64796
9.8 CRITICAL

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to …

Jul 22, 2026
CVE-2026-64793
9.1 CRITICAL

Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or …

Jul 22, 2026
CVE-2025-50329
9.8 CRITICAL

An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

Jul 22, 2026
CVE-2026-16624
9.6 CRITICAL

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then …

Jul 22, 2026
CVE-2026-46738
9.1 CRITICAL

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access …

Jul 22, 2026
CVE-2026-40712
9.1 CRITICAL

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access …

Jul 22, 2026
CVE-2026-16606
9.8 CRITICAL

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on …

Jul 22, 2026
CVE-2026-2395
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. …

Jul 22, 2026
CVE-2026-62144
9.1 CRITICAL

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management …

Jul 22, 2026
CVE-2026-50252
9.3 CRITICAL

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases …

Jul 22, 2026
CVE-2026-16232
9.1 CRITICAL KEV

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it …

Jul 22, 2026
CVE-2026-65590
9.8 CRITICAL

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only …

Jul 22, 2026
CVE-2026-16424
9.6 CRITICAL

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially …

Jul 21, 2026
CVE-2026-16419
9.6 CRITICAL

Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox …

Jul 21, 2026
CVE-2026-62549
9.6 CRITICAL

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows …

Jul 21, 2026
CVE-2026-62546
9.1 CRITICAL

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows …

Jul 21, 2026
CVE-2026-61245
9.8 CRITICAL

Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability …

Jul 21, 2026
CVE-2026-61244
9.1 CRITICAL

Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Argentina product of Oracle PeopleSoft (component: Manufacturing). The supported version that is affected is 9.1. Easily exploitable vulnerability …

Jul 21, 2026
CVE-2026-61242
9.9 CRITICAL

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable …

Jul 21, 2026
CVE-2026-61239
9.9 CRITICAL

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable …

Jul 21, 2026
CVE-2026-61238
9.1 CRITICAL

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: eProcurement). The supported version that is affected is 9.1. Easily exploitable …

Jul 21, 2026
CVE-2026-61237
9.9 CRITICAL

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable …

Jul 21, 2026
CVE-2026-61235
9.1 CRITICAL

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is …

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.