CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55558
5.9 MEDIUM

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS …

Aug 20, 2026
CVE-2026-44725
6.6 MEDIUM

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, …

Aug 20, 2026
CVE-2026-76634
6.5 MEDIUM

WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by …

Aug 20, 2026
CVE-2026-76989
5.3 MEDIUM

A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the file source/src/enet_encap/encap.cc of the component TCP Encapsulation Receive …

Aug 20, 2026
CVE-2026-76988
5.3 MEDIUM

A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forward_open of the file cipconnectionmanager.cc of the component ForwardOpen Handler. Executing a …

Aug 20, 2026
CVE-2026-28163
5.3 MEDIUM

Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through …

Aug 20, 2026
CVE-2026-21784
4.8 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized …

Aug 20, 2026
CVE-2025-62306
5.0 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were …

Aug 20, 2026
CVE-2025-62300
5.9 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable …

Aug 20, 2026
CVE-2025-62299
6.6 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege …

Aug 20, 2026
CVE-2026-73402
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.

Aug 20, 2026
CVE-2026-66647
6.5 MEDIUM

Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.

Aug 20, 2026
CVE-2026-66601
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.

Aug 20, 2026
CVE-2026-66595
5.9 MEDIUM

Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

Aug 20, 2026
CVE-2026-66586
6.6 MEDIUM

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Aug 20, 2026
CVE-2025-62307
5.4 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.

Aug 20, 2026
CVE-2025-53999
6.5 MEDIUM

Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.

Aug 20, 2026
CVE-2026-77067
5.0 MEDIUM

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook …

Aug 20, 2026
CVE-2026-77066
5.0 MEDIUM

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), …

Aug 20, 2026
CVE-2026-73199
6.5 MEDIUM

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight …

Aug 20, 2026
CVE-2026-73196
4.3 MEDIUM

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized …

Aug 20, 2026
CVE-2026-77014
5.3 MEDIUM

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping …

Aug 20, 2026
CVE-2026-14953
4.3 MEDIUM

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

Aug 20, 2026
CVE-2026-14949
6.5 MEDIUM

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts …

Aug 20, 2026
CVE-2026-71368
6.1 MEDIUM

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

Aug 20, 2026
CVE-2026-74992
6.8 MEDIUM

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not …

Aug 20, 2026
CVE-2026-19697
6.8 MEDIUM

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file …

Aug 20, 2026
CVE-2026-19615
6.8 MEDIUM

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users …

Aug 20, 2026
CVE-2026-17153
5.3 MEDIUM

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to …

Aug 20, 2026
CVE-2026-13405
6.6 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later …

Aug 20, 2026
CVE-2026-76957
4.9 MEDIUM

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and …

Aug 20, 2026
CVE-2026-76956
5.9 MEDIUM

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, …

Aug 20, 2026
CVE-2026-76800
6.3 MEDIUM

A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the …

Aug 20, 2026
CVE-2026-76799
5.3 MEDIUM

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database …

Aug 20, 2026
CVE-2026-76785
6.3 MEDIUM

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument …

Aug 20, 2026
CVE-2022-4996
5.3 MEDIUM

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point …

Aug 20, 2026
CVE-2026-76929
4.7 MEDIUM

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76927
4.7 MEDIUM

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76924
5.5 MEDIUM

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76923
5.5 MEDIUM

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76922
5.5 MEDIUM

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76921
5.5 MEDIUM

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76920
4.7 MEDIUM

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76919
5.3 MEDIUM

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76918
5.5 MEDIUM

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76917
5.5 MEDIUM

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76889
4.7 MEDIUM

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76883
4.7 MEDIUM

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76882
4.7 MEDIUM

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76881
4.7 MEDIUM

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.