CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76057
4.3 MEDIUM

The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions …

Aug 22, 2026
CVE-2026-75027
5.3 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin …

Aug 22, 2026
CVE-2026-53541
4.3 MEDIUM

OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly …

Aug 21, 2026
CVE-2026-53524
6.5 MEDIUM

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() …

Aug 21, 2026
CVE-2026-34949
6.5 MEDIUM

Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a …

Aug 21, 2026
CVE-2026-53509
5.7 MEDIUM

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a …

Aug 21, 2026
CVE-2026-53497
5.3 MEDIUM

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of …

Aug 21, 2026
CVE-2026-53487
4.3 MEDIUM

Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do …

Aug 21, 2026
CVE-2026-53468
4.6 MEDIUM

Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in …

Aug 21, 2026
CVE-2026-43980
6.3 MEDIUM

Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored …

Aug 21, 2026
CVE-2026-34836
6.5 MEDIUM

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without …

Aug 21, 2026
CVE-2026-33047
4.3 MEDIUM

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned …

Aug 21, 2026
CVE-2026-77220
6.5 MEDIUM

PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buffer in the document dictionary …

Aug 21, 2026
CVE-2026-69236
6.1 MEDIUM

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to …

Aug 21, 2026
CVE-2026-69235
6.1 MEDIUM

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to …

Aug 21, 2026
CVE-2026-69234
6.1 MEDIUM

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated attacker to …

Aug 21, 2026
CVE-2026-69233
5.5 MEDIUM

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker …

Aug 21, 2026
CVE-2026-69232
5.5 MEDIUM

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to …

Aug 21, 2026
CVE-2026-69231
5.5 MEDIUM

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to …

Aug 21, 2026
CVE-2026-69230
5.5 MEDIUM

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged attacker …

Aug 21, 2026
CVE-2026-69229
5.4 MEDIUM

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arbitrary HTML …

Aug 21, 2026
CVE-2026-69228
5.3 MEDIUM

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker to access a …

Aug 21, 2026
CVE-2026-69225
5.9 MEDIUM

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenticated attacker to …

Aug 21, 2026
CVE-2026-69224
5.9 MEDIUM

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstances allow a remote, …

Aug 21, 2026
CVE-2026-55168
6.5 MEDIUM

Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and copies them into live application …

Aug 21, 2026
CVE-2026-53656
6.3 MEDIUM

FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone/server/app.py and the /media …

Aug 21, 2026
CVE-2026-53572
5.9 MEDIUM

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password …

Aug 21, 2026
CVE-2026-45271
5.5 MEDIUM

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 validation helper, …

Aug 21, 2026
CVE-2026-44517
6.3 MEDIUM

Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confine Git repository subdirectories …

Aug 21, 2026
CVE-2026-76876
5.9 MEDIUM

Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiting an unconditional authorization policy on the …

Aug 21, 2026
CVE-2026-27463
5.3 MEDIUM

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains …

Aug 21, 2026
CVE-2026-77795
6.3 MEDIUM

A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to …

Aug 21, 2026
CVE-2026-63466
4.1 MEDIUM

Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escape to an identity function before rendering action and path templates. …

Aug 21, 2026
CVE-2026-63004
5.5 MEDIUM

Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-controlled parameters.url value from src/lib/addons/webhook.ts …

Aug 21, 2026
CVE-2026-54681
4.1 MEDIUM

DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into …

Aug 21, 2026
CVE-2026-53762
6.2 MEDIUM

VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRYPT_BACKEND route SHA-256 and SHA-512 volume-header …

Aug 21, 2026
CVE-2026-77237
6.5 MEDIUM

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSE_QUEUE_SETS=1 to read privileged kernel …

Aug 21, 2026
CVE-2026-70656
4.9 MEDIUM

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.5.1 …

Aug 21, 2026
CVE-2026-75928
5.3 MEDIUM

The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a remote, unauthenticated attacker to read information about other …

Aug 21, 2026
CVE-2026-62313
4.3 MEDIUM

Incus is a system container and virtual machine manager. Prior to version 7.3.0, project-level enforcement of `restricted.containers.privilege=isolated` can be trivially bypassed, allowing a user to …

Aug 21, 2026
CVE-2026-50278
6.5 MEDIUM

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The …

Aug 21, 2026
CVE-2026-59318
6.5 MEDIUM

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a …

Aug 21, 2026
CVE-2026-59308
4.2 MEDIUM

In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared …

Aug 21, 2026
CVE-2026-19848
6.5 MEDIUM

The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers …

Aug 21, 2026
CVE-2026-17559
5.3 MEDIUM

The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password …

Aug 21, 2026
CVE-2026-16650
5.3 MEDIUM

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to …

Aug 21, 2026
CVE-2026-15150
5.3 MEDIUM

The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing …

Aug 21, 2026
CVE-2026-15046
4.2 MEDIUM

The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to …

Aug 21, 2026
CVE-2026-77769
6.5 MEDIUM

The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied projectId, …

Aug 21, 2026
CVE-2026-77768
6.5 MEDIUM

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries …

Aug 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.