CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-33389
7.5 HIGH

An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's …

Sep 8, 2026
CVE-2026-33388
7.4 HIGH

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges …

Sep 8, 2026
CVE-2026-79602
8.8 HIGH

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

Sep 8, 2026
CVE-2026-77106
8.8 HIGH

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command …

Sep 8, 2026
CVE-2026-77105
8.8 HIGH

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.

Sep 8, 2026
CVE-2026-77104
7.5 HIGH

CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77103
7.5 HIGH

CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77102
7.5 HIGH

CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77101
7.5 HIGH

CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77097
8.2 HIGH

Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics …

Sep 8, 2026
CVE-2026-77091
7.8 HIGH

DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.

Sep 8, 2026
CVE-2026-75021
8.1 HIGH

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector …

Sep 8, 2026
CVE-2026-86713
7.1 HIGH

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter …

Sep 8, 2026
CVE-2026-86712
8.8 HIGH

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. …

Sep 8, 2026
CVE-2026-86711
7.4 HIGH

electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke …

Sep 8, 2026
CVE-2026-80219
8.7 HIGH

A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and …

Sep 8, 2026
CVE-2026-77968
8.2 HIGH

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime …

Sep 8, 2026
CVE-2026-74860
8.5 HIGH

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing …

Sep 8, 2026
CVE-2026-3174
7.5 HIGH

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth …

Sep 8, 2026
CVE-2026-16502
8.8 HIGH

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 …

Sep 8, 2026
CVE-2026-9331
7.1 HIGH

The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service …

Sep 8, 2026
CVE-2026-67367
8.6 HIGH

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions …

Sep 8, 2026
CVE-2026-62650
8.8 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing …

Sep 8, 2026
CVE-2026-62649
7.5 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing …

Sep 8, 2026
CVE-2026-62648
7.5 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not …

Sep 8, 2026
CVE-2026-62647
7.4 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session …

Sep 8, 2026
CVE-2026-62646
7.4 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in …

Sep 8, 2026
CVE-2026-34223
8.2 HIGH

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All …

Sep 8, 2026
CVE-2026-84820
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

Sep 8, 2026
CVE-2026-84818
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

Sep 8, 2026
CVE-2026-84817
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

Sep 8, 2026
CVE-2026-81806
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from …

Sep 8, 2026
CVE-2026-81798
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through …

Sep 8, 2026
CVE-2026-81790
7.5 HIGH

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási …

Sep 8, 2026
CVE-2026-81781
7.1 HIGH

Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a …

Sep 8, 2026
CVE-2026-76561
7.2 HIGH

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile …

Sep 8, 2026
CVE-2026-71375
7.4 HIGH

Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before …

Sep 8, 2026
CVE-2026-48888
7.5 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

Sep 8, 2026
CVE-2026-76967
7.8 HIGH

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the …

Sep 8, 2026
CVE-2026-76958
8.5 HIGH

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially …

Sep 8, 2026
CVE-2026-66767
7.7 HIGH

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously …

Sep 8, 2026
CVE-2026-86544
8.1 HIGH

knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit …

Sep 7, 2026
CVE-2026-86541
8.3 HIGH

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers …

Sep 7, 2026
CVE-2026-86540
7.8 HIGH

knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious …

Sep 7, 2026
CVE-2026-86539
7.2 HIGH

knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can …

Sep 7, 2026
CVE-2026-86538
7.5 HIGH

knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply …

Sep 7, 2026
CVE-2026-86439
8.8 HIGH

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project …

Sep 7, 2026
CVE-2026-86438
7.2 HIGH

Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP …

Sep 7, 2026
CVE-2026-86437
7.2 HIGH

Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over …

Sep 7, 2026
CVE-2026-86287
7.5 HIGH

Net::IP::LPM versions before 1.12 for Perl accept malformed prefix lengths. Non-numeric and non-ASCII prefix lengths are accepted and treated as 0. Integers over 31 bits …

Sep 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.