CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-49132
5.4 MEDIUM

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate …

Aug 3, 2026
CVE-2026-49131
5.4 MEDIUM

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by …

Aug 3, 2026
CVE-2026-48061
5.9 MEDIUM

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the …

Aug 3, 2026
CVE-2026-18738
4.7 MEDIUM

Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by …

Aug 3, 2026
CVE-2026-18737
6.5 MEDIUM

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value …

Aug 3, 2026
CVE-2026-18736
5.0 MEDIUM

Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying …

Aug 3, 2026
CVE-2026-18648
5.3 MEDIUM

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the …

Aug 3, 2026
CVE-2026-18646
5.3 MEDIUM

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component Author Name …

Aug 3, 2026
CVE-2026-18645
5.4 MEDIUM

A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin …

Aug 3, 2026
CVE-2026-58139
6.5 MEDIUM

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS …

Aug 3, 2026
CVE-2026-18655
6.5 MEDIUM

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated …

Aug 3, 2026
CVE-2026-18654
6.8 MEDIUM

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow …

Aug 3, 2026
CVE-2026-18644
5.4 MEDIUM

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the component …

Aug 3, 2026
CVE-2026-18632
6.3 MEDIUM

A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component …

Aug 3, 2026
CVE-2026-18631
6.3 MEDIUM

A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/src/main/java/com/jeequan/jeepay/mgr/ctrl/sysuser/SysLogController.java of the component PreAuthorize Handler. …

Aug 3, 2026
CVE-2026-38446
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title …

Aug 3, 2026
CVE-2026-38444
6.1 MEDIUM

osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored …

Aug 3, 2026
CVE-2026-40717
6.6 MEDIUM

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially …

Aug 3, 2026
CVE-2026-69153
5.3 MEDIUM

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior …

Aug 3, 2026
CVE-2026-68930
6.5 MEDIUM

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened …

Aug 3, 2026
CVE-2026-67612
4.8 MEDIUM

OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that allows authenticated administrators to inject arbitrary HTML and JavaScript …

Aug 3, 2026
CVE-2026-18610
5.3 MEDIUM

A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. …

Aug 3, 2026
CVE-2026-18604
5.3 MEDIUM

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the component com.gogii.textplus. …

Aug 3, 2026
CVE-2026-18477
4.4 MEDIUM

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed …

Aug 3, 2026
CVE-2026-18651
5.4 MEDIUM

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the …

Aug 3, 2026
CVE-2026-18508
4.4 MEDIUM

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory …

Aug 3, 2026
CVE-2026-15430
6.2 MEDIUM

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to …

Aug 3, 2026
CVE-2026-69094
4.3 MEDIUM

Admidio before 5.0.11 contains an insecure direct object reference vulnerability in the save_temporary mode of mylist_function.php that allows authenticated users to hijack list configurations. Attackers …

Aug 3, 2026
CVE-2026-69093
4.6 MEDIUM

Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs persistent Category Report configuration changes based on GET parameters (delete and copy). An …

Aug 3, 2026
CVE-2026-69092
6.5 MEDIUM

Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messages to the HTTP response. Unauthenticated attackers …

Aug 3, 2026
CVE-2026-69090
4.9 MEDIUM

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role administrators to delete, activate, deactivate, or edit roles belonging to …

Aug 3, 2026
CVE-2026-69087
6.5 MEDIUM

The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action evaluates user-supplied form data inside Twig expressions, …

Aug 3, 2026
CVE-2026-68585
5.8 MEDIUM

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata including title for publish-forbidden documents without publish-access …

Aug 3, 2026
CVE-2026-56609
4.8 MEDIUM

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 …

Aug 3, 2026
CVE-2026-68742
5.5 MEDIUM

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. …

Aug 3, 2026
CVE-2026-63563
6.5 MEDIUM

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When …

Aug 3, 2026
CVE-2026-62416
5.3 MEDIUM

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the …

Aug 3, 2026
CVE-2026-60011
5.3 MEDIUM

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

Aug 3, 2026
CVE-2026-28147
5.4 MEDIUM

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects …

Aug 3, 2026
CVE-2026-18593
5.6 MEDIUM

A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management …

Aug 3, 2026
CVE-2026-18592
4.7 MEDIUM

A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email …

Aug 3, 2026
CVE-2026-18590
6.3 MEDIUM

A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation …

Aug 3, 2026
CVE-2026-12259
5.3 MEDIUM

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This …

Aug 3, 2026
CVE-2026-9593
6.7 MEDIUM

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing …

Aug 3, 2026
CVE-2026-16565
4.3 MEDIUM

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users …

Aug 3, 2026
CVE-2026-16564
4.3 MEDIUM

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status …

Aug 3, 2026
CVE-2026-16563
6.5 MEDIUM

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, …

Aug 3, 2026
CVE-2026-16297
4.1 MEDIUM

The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP …

Aug 3, 2026
CVE-2026-16289
4.3 MEDIUM

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a …

Aug 3, 2026
CVE-2026-16057
6.5 MEDIUM

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.