CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-78572
8.1 HIGH

The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. …

Aug 25, 2026
CVE-2026-75037
7.0 HIGH

Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit …

Aug 25, 2026
CVE-2026-49050
8.8 HIGH

General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which …

Aug 25, 2026
CVE-2026-16231
8.1 HIGH

hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during …

Aug 25, 2026
CVE-2026-78566
8.1 HIGH

The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated …

Aug 25, 2026
CVE-2026-78563
7.2 HIGH

The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization …

Aug 25, 2026
CVE-2026-78562
8.1 HIGH

The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2. This makes it possible for …

Aug 25, 2026
CVE-2026-63587
8.6 HIGH

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry …

Aug 25, 2026
CVE-2026-67578
7.5 HIGH

FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter …

Aug 25, 2026
CVE-2026-19851
7.7 HIGH

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created …

Aug 25, 2026
CVE-2026-18328
7.2 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' …

Aug 25, 2026
CVE-2026-18323
7.2 HIGH

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save …

Aug 25, 2026
CVE-2026-16601
8.8 HIGH

The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in …

Aug 25, 2026
CVE-2026-69665
7.8 HIGH

SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in …

Aug 25, 2026
CVE-2026-68960
8.5 HIGH

A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in …

Aug 25, 2026
CVE-2026-68959
8.5 HIGH

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a …

Aug 25, 2026
CVE-2026-68062
8.5 HIGH

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a …

Aug 25, 2026
CVE-2026-66109
7.8 HIGH

A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to …

Aug 25, 2026
CVE-2026-78654
7.3 HIGH

A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads …

Aug 25, 2026
CVE-2026-78478
8.1 HIGH

The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated …

Aug 25, 2026
CVE-2026-78637
7.3 HIGH

A vulnerability was detected in Fdawgs node-poppler up to 9.1.2/10.0.1. The impacted element is the function pdfInfo/pdfToText/pdfToCairo/pdfToPpm/pdfImages/pdfToHtml/pdfToPs/pdfFonts/pdfDetach/pdfAttach/pdfSeparate/pdfUnite of the file src/index.js of the component Argument …

Aug 25, 2026
CVE-2026-19892
8.8 HIGH

The InfusedWoo Pro plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 5.1.17. This is due …

Aug 25, 2026
CVE-2026-78685
8.8 HIGH

Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML …

Aug 25, 2026
CVE-2026-78682
7.5 HIGH

NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested …

Aug 25, 2026
CVE-2026-78681
7.5 HIGH

NLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in multiple modules, which honors entity declarations in document DTDs. Attackers can craft XML payloads with …

Aug 25, 2026
CVE-2026-78680
7.8 HIGH

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary …

Aug 25, 2026
CVE-2026-78677
7.5 HIGH

GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter …

Aug 25, 2026
CVE-2026-78675
8.4 HIGH

GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. …

Aug 25, 2026
CVE-2026-76846
7.5 HIGH

Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit …

Aug 25, 2026
CVE-2026-75574
8.8 HIGH

The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write …

Aug 25, 2026
CVE-2026-72700
7.5 HIGH

The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() …

Aug 25, 2026
CVE-2026-72696
8.4 HIGH

Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable …

Aug 25, 2026
CVE-2026-72695
8.1 HIGH

Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames …

Aug 25, 2026
CVE-2026-56709
7.5 HIGH

Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to …

Aug 25, 2026
CVE-2026-56707
7.7 HIGH

Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render …

Aug 25, 2026
CVE-2026-56703
7.2 HIGH

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can …

Aug 25, 2026
CVE-2026-56702
8.8 HIGH

Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a …

Aug 25, 2026
CVE-2026-34968
8.1 HIGH

Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An …

Aug 25, 2026
CVE-2026-66766
7.5 HIGH

SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted …

Aug 25, 2026
CVE-2026-78284
8.6 HIGH

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

Aug 24, 2026
CVE-2026-78282
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.

Aug 24, 2026
CVE-2026-78268
7.5 HIGH

Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.

Aug 24, 2026
CVE-2026-78264
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.

Aug 24, 2026
CVE-2026-78263
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.

Aug 24, 2026
CVE-2026-78259
7.3 HIGH

Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.

Aug 24, 2026
CVE-2026-77384
7.5 HIGH

libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but …

Aug 24, 2026
CVE-2026-32561
8.8 HIGH

Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

Aug 24, 2026
CVE-2026-32560
8.8 HIGH

Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.

Aug 24, 2026
CVE-2026-32556
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.

Aug 24, 2026
CVE-2026-7455
7.8 HIGH

A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to …

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.