CVE Database

57505+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-15931
6.1 MEDIUM

The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when …

Aug 3, 2026
CVE-2026-15383
6.1 MEDIUM

The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST …

Aug 3, 2026
CVE-2026-15260
4.3 MEDIUM

The GEO my WP WordPress plugin before 4.5.5.3 does not perform any ownership or capability check on two of its logged-in AJAX actions, allowing users …

Aug 3, 2026
CVE-2026-15254
6.5 MEDIUM

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing shortcode, and its per-user result scoping fails …

Aug 3, 2026
CVE-2026-13340
6.1 MEDIUM

The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it registers and …

Aug 3, 2026
CVE-2025-15673
4.9 MEDIUM

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a …

Aug 3, 2026
CVE-2026-6695
5.5 MEDIUM

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro …

Aug 3, 2026
CVE-2026-6694
5.5 MEDIUM

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing …

Aug 3, 2026
CVE-2026-18585
4.3 MEDIUM

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is …

Aug 3, 2026
CVE-2026-18584
5.4 MEDIUM

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the …

Aug 3, 2026
CVE-2026-18583
5.3 MEDIUM

A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/server/mms_mapping/mms_mapping.c of the component MMS …

Aug 3, 2026
CVE-2026-20498
6.0 MEDIUM

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a …

Aug 3, 2026
CVE-2026-20497
6.0 MEDIUM

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Aug 3, 2026
CVE-2026-20496
4.4 MEDIUM

In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a …

Aug 3, 2026
CVE-2026-20494
5.5 MEDIUM

In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a …

Aug 3, 2026
CVE-2026-20493
4.4 MEDIUM

In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if …

Aug 3, 2026
CVE-2026-20492
5.5 MEDIUM

In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User …

Aug 3, 2026
CVE-2026-20491
5.5 MEDIUM

In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with …

Aug 3, 2026
CVE-2026-20490
4.4 MEDIUM

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if …

Aug 3, 2026
CVE-2026-20489
4.4 MEDIUM

In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has …

Aug 3, 2026
CVE-2026-20488
4.4 MEDIUM

In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor …

Aug 3, 2026
CVE-2026-20486
6.7 MEDIUM

In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor …

Aug 3, 2026
CVE-2026-20485
6.0 MEDIUM

In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Aug 3, 2026
CVE-2026-20484
4.4 MEDIUM

In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor …

Aug 3, 2026
CVE-2026-20482
6.5 MEDIUM

In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no …

Aug 3, 2026
CVE-2026-20481
6.0 MEDIUM

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Aug 3, 2026
CVE-2026-20480
5.5 MEDIUM

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service …

Aug 3, 2026
CVE-2026-20478
5.5 MEDIUM

In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service …

Aug 3, 2026
CVE-2026-20477
6.0 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Aug 3, 2026
CVE-2026-20476
5.5 MEDIUM

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with …

Aug 3, 2026
CVE-2026-20475
6.0 MEDIUM

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Aug 3, 2026
CVE-2026-20474
6.0 MEDIUM

In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious …

Aug 3, 2026
CVE-2026-20473
6.0 MEDIUM

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Aug 3, 2026
CVE-2026-20472
4.4 MEDIUM

In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if …

Aug 3, 2026
CVE-2026-20471
4.6 MEDIUM

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if …

Aug 3, 2026
CVE-2026-20470
6.2 MEDIUM

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution …

Aug 3, 2026
CVE-2026-20469
6.0 MEDIUM

In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious …

Aug 3, 2026
CVE-2026-20468
6.0 MEDIUM

In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious …

Aug 3, 2026
CVE-2026-20467
6.0 MEDIUM

In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a …

Aug 3, 2026
CVE-2026-20466
6.1 MEDIUM

In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if …

Aug 3, 2026
CVE-2026-20464
6.5 MEDIUM

In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if …

Aug 3, 2026
CVE-2026-18582
5.3 MEDIUM

A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Reporting_RCBWriteAccessHandler of the file src/iec61850/server/mms_mapping/reporting.c of the component …

Aug 3, 2026
CVE-2026-68583
5.4 MEDIUM

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator …

Aug 2, 2026
CVE-2026-68582
6.5 MEDIUM

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the …

Aug 2, 2026
CVE-2025-71401
5.9 MEDIUM

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to …

Aug 2, 2026
CVE-2026-12231
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and …

Aug 2, 2026
CVE-2026-18573
6.5 MEDIUM

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm …

Aug 2, 2026
CVE-2026-18572
6.5 MEDIUM

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A …

Aug 2, 2026
CVE-2026-18571
6.6 MEDIUM

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator …

Aug 2, 2026
CVE-2026-18570
5.4 MEDIUM

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and …

Aug 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.