CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-71910
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and …

Aug 24, 2026
CVE-2026-71909
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before …

Aug 24, 2026
CVE-2026-71908
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip …

Aug 24, 2026
CVE-2026-71907
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before …

Aug 24, 2026
CVE-2026-71906
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask …

Aug 24, 2026
CVE-2026-71905
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and …

Aug 24, 2026
CVE-2026-71904
7.2 HIGH

Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the …

Aug 24, 2026
CVE-2026-78465
7.0 HIGH

A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation …

Aug 24, 2026
CVE-2026-66908
7.5 HIGH

Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can …

Aug 24, 2026
CVE-2026-66907
7.5 HIGH

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 …

Aug 24, 2026
CVE-2026-19685
7.1 HIGH

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user …

Aug 24, 2026
CVE-2025-36940
8.8 HIGH

Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)

Aug 24, 2026
CVE-2026-71366
7.7 HIGH

A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs …

Aug 24, 2026
CVE-2026-71364
7.2 HIGH

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project …

Aug 24, 2026
CVE-2026-21752
7.5 HIGH

HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting …

Aug 24, 2026
CVE-2026-13212
8.8 HIGH

The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written …

Aug 24, 2026
CVE-2025-68825
7.5 HIGH

HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communications.

Aug 24, 2026
CVE-2026-78414
8.0 HIGH

Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker …

Aug 24, 2026
CVE-2026-39915
8.1 HIGH

TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized …

Aug 24, 2026
CVE-2026-78376
8.8 HIGH

A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.

Aug 24, 2026
CVE-2026-78367
7.0 HIGH

A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive …

Aug 24, 2026
CVE-2026-78248
7.3 HIGH

A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the …

Aug 24, 2026
CVE-2026-76848
7.5 HIGH

TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array …

Aug 24, 2026
CVE-2026-76847
8.8 HIGH

act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact …

Aug 24, 2026
CVE-2026-76844
7.4 HIGH

webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a …

Aug 24, 2026
CVE-2026-76843
7.8 HIGH

The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a …

Aug 24, 2026
CVE-2026-76842
8.2 HIGH

The Mercado Pago Node.js SDK interpolates caller-supplied identifiers into API request paths without percent-encoding them, so characters that are structural in a URL survive into …

Aug 24, 2026
CVE-2026-76841
8.8 HIGH

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites …

Aug 24, 2026
CVE-2026-59567
8.8 HIGH

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a …

Aug 24, 2026
CVE-2026-59566
8.4 HIGH

A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.

Aug 24, 2026
CVE-2026-59565
8.8 HIGH

A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.

Aug 24, 2026
CVE-2026-30512
7.8 HIGH

A local privilege escalation vulnerability exists in the Restricted Access (Kiosk) Mode implementation of Scheidt & Bachmann entervo HMI prior to V2 R5 P0 M5. …

Aug 24, 2026
CVE-2026-21751
7.4 HIGH

HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if …

Aug 24, 2026
CVE-2026-78247
7.3 HIGH

A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of …

Aug 24, 2026
CVE-2026-21756
7.2 HIGH

HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code …

Aug 24, 2026
CVE-2026-78270
7.6 HIGH

Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.

Aug 24, 2026
CVE-2026-78246
7.3 HIGH

A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin …

Aug 24, 2026
CVE-2026-66671
8.1 HIGH

Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.

Aug 24, 2026
CVE-2026-66670
8.1 HIGH

Unauthenticated Local File Inclusion in Måne <= 1.7 versions.

Aug 24, 2026
CVE-2026-66623
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Social Media & Share Icons <= 2.9.9 versions.

Aug 24, 2026
CVE-2026-66610
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Urna <= 2.6.2 versions.

Aug 24, 2026
CVE-2026-66599
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WPComplete <= 2.9.5.6 versions.

Aug 24, 2026
CVE-2026-66585
7.5 HIGH

Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.

Aug 24, 2026
CVE-2026-66584
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting List <= 3.19.16 versions.

Aug 24, 2026
CVE-2026-32478
8.5 HIGH

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

Aug 24, 2026
CVE-2026-32477
8.6 HIGH

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

Aug 24, 2026
CVE-2026-32476
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.

Aug 24, 2026
CVE-2026-32471
8.5 HIGH

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

Aug 24, 2026
CVE-2026-28190
7.1 HIGH

Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.

Aug 24, 2026
CVE-2026-28171
8.6 HIGH

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

Aug 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.