CVE Database

5195+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-71514
2.5 LOW

NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus …

Aug 22, 2026
CVE-2026-14187
2.7 LOW

The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role …

Aug 22, 2026
CVE-2026-33333
3.5 LOW

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has …

Aug 21, 2026
CVE-2026-69238
3.5 LOW

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.5 and prior that allows a remote, highly priviliged attacker to insert arbitrary …

Aug 21, 2026
CVE-2026-69237
3.8 LOW

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.3 and prior that allows a remote attacker with administrative privileges to insert …

Aug 21, 2026
CVE-2026-18356
3.7 LOW

The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's …

Aug 21, 2026
CVE-2026-13176
2.7 LOW

The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access …

Aug 21, 2026
CVE-2026-66721
2.7 LOW

Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the …

Aug 21, 2026
CVE-2026-19435
2.7 LOW

The Duplicate Post WordPress plugin before 1.5.6 does not check the user's capabilities before returning post data, allowing users with a delegated role to read …

Aug 21, 2026
CVE-2026-19085
2.7 LOW

The Duplicate Post WordPress plugin before 1.5.6 does not check that a user may read the content of a post before duplicating it, allowing users …

Aug 21, 2026
CVE-2026-16577
2.7 LOW

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not validate a client-supplied payment amount against the vendor's actual outstanding balance …

Aug 21, 2026
CVE-2026-14325
3.5 LOW

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not escape one of its settings before using it …

Aug 21, 2026
CVE-2026-76137
3.3 LOW

Missing authentication for critical function vulnerability exists in VOCALOID6. Any process running under the same local user account as a running VOCALOID6 Editor instance may …

Aug 21, 2026
CVE-2026-43679
2.4 LOW

This issue was addressed with improved permissions checking. This issue is fixed in watchOS 26.4. An attacker with physical access to a locked Apple Watch …

Aug 21, 2026
CVE-2026-77648
2.2 LOW

In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service …

Aug 20, 2026
CVE-2026-49245
3.7 LOW

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads …

Aug 20, 2026
CVE-2026-77640
3.7 LOW

tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib …

Aug 20, 2026
CVE-2026-77151
3.7 LOW

A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing …

Aug 20, 2026
CVE-2026-49996
3.7 LOW

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a …

Aug 20, 2026
CVE-2026-64846
2.8 LOW

Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit …

Aug 20, 2026
CVE-2026-18283
2.4 LOW

Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication …

Aug 20, 2026
CVE-2026-18280
3.9 LOW

Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES …

Aug 20, 2026
CVE-2026-18278
3.5 LOW

Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An …

Aug 20, 2026
CVE-2026-73542
3.7 LOW

Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. …

Aug 20, 2026
CVE-2026-19699
2.7 LOW

The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor …

Aug 20, 2026
CVE-2026-76926
3.1 LOW

BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76891
3.1 LOW

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76890
3.1 LOW

Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76888
3.1 LOW

RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76887
3.1 LOW

Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76885
3.1 LOW

Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76884
3.1 LOW

ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76371
2.7 LOW

In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add …

Aug 19, 2026
CVE-2026-76369
2.7 LOW

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The …

Aug 19, 2026
CVE-2026-76368
2.7 LOW

In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that …

Aug 19, 2026
CVE-2026-76361
2.7 LOW

In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections …

Aug 19, 2026
CVE-2026-76348
3.8 LOW

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send …

Aug 19, 2026
CVE-2026-75476
3.1 LOW

Tanium addressed a compression bomb vulnerability in Threat Response.

Aug 19, 2026
CVE-2026-18102
3.5 LOW

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.

Aug 19, 2026
CVE-2026-11617
3.1 LOW

Tanium addressed a compression bomb vulnerability in Findings.

Aug 19, 2026
CVE-2026-16891
3.3 LOW

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out-of-bounds read.

Aug 19, 2026
CVE-2026-16890
3.6 LOW

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information or cause a denial of service …

Aug 19, 2026
CVE-2026-16888
3.7 LOW

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to a path traversal vulnerability.

Aug 19, 2026
CVE-2026-75583
3.5 LOW

keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability that allows authenticated attackers to reach private network addresses …

Aug 19, 2026
CVE-2026-18839
2.2 LOW

An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who …

Aug 5, 2026
CVE-2026-70600
3.1 LOW

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup …

Aug 5, 2026
CVE-2026-70598
3.9 LOW

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data …

Aug 5, 2026
CVE-2026-12730
3.8 LOW

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim …

Aug 5, 2026
CVE-2026-8029
3.9 LOW

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db …

Aug 5, 2026
CVE-2026-16993
3.7 LOW

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an …

Aug 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.