CVE Database

45217+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-28167
7.5 HIGH

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

Aug 24, 2026
CVE-2026-28166
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.

Aug 24, 2026
CVE-2026-28162
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.

Aug 24, 2026
CVE-2026-28153
7.5 HIGH

Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.

Aug 24, 2026
CVE-2026-28152
8.1 HIGH

Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.

Aug 24, 2026
CVE-2026-28151
8.1 HIGH

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

Aug 24, 2026
CVE-2026-78245
7.3 HIGH

A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. …

Aug 24, 2026
CVE-2026-78244
7.3 HIGH

A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a …

Aug 24, 2026
CVE-2026-76172
7.5 HIGH

fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and …

Aug 24, 2026
CVE-2026-10582
7.4 HIGH

Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the …

Aug 24, 2026
CVE-2026-78317
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-78316
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-78315
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-78314
8.8 HIGH

SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.

Aug 24, 2026
CVE-2026-75975
7.5 HIGH

fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text …

Aug 24, 2026
CVE-2026-75931
7.5 HIGH

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a …

Aug 24, 2026
CVE-2026-75899
7.5 HIGH

fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time …

Aug 24, 2026
CVE-2026-78202
7.3 HIGH

A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results …

Aug 24, 2026
CVE-2026-78201
7.3 HIGH

A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the …

Aug 24, 2026
CVE-2026-78199
7.3 HIGH

A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of …

Aug 24, 2026
CVE-2026-78198
7.3 HIGH

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such …

Aug 24, 2026
CVE-2026-78197
7.3 HIGH

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of …

Aug 24, 2026
CVE-2026-59561
7.8 HIGH

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in …

Aug 24, 2026
CVE-2026-78213
8.7 HIGH

Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary …

Aug 24, 2026
CVE-2026-78212
7.5 HIGH

4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to …

Aug 24, 2026
CVE-2026-78182
7.3 HIGH

A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans …

Aug 24, 2026
CVE-2026-78181
7.3 HIGH

A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can …

Aug 24, 2026
CVE-2026-78180
7.3 HIGH

A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component …

Aug 24, 2026
CVE-2026-19200
8.9 HIGH

The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL …

Aug 24, 2026
CVE-2026-78178
7.3 HIGH

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of …

Aug 24, 2026
CVE-2026-78171
7.3 HIGH

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/processlogin.php. The …

Aug 24, 2026
CVE-2026-78170
8.8 HIGH

A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of …

Aug 24, 2026
CVE-2026-78209
8.2 HIGH

exceljs through 4.4.0 fails to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported …

Aug 24, 2026
CVE-2026-78208
7.5 HIGH

exceljs through 4.4.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to …

Aug 24, 2026
CVE-2026-78206
7.5 HIGH

exceljs through 4.4.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload …

Aug 24, 2026
CVE-2026-78203
7.1 HIGH

Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their …

Aug 24, 2026
CVE-2026-78161
7.3 HIGH

A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation …

Aug 24, 2026
CVE-2026-78157
7.4 HIGH

A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation …

Aug 24, 2026
CVE-2026-78156
7.4 HIGH

A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s6a-path.c of the component S6a …

Aug 24, 2026
CVE-2026-78147
7.3 HIGH

A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing …

Aug 23, 2026
CVE-2026-78143
7.3 HIGH

A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident …

Aug 23, 2026
CVE-2026-78141
7.4 HIGH

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of the argument cmdinput leads …

Aug 23, 2026
CVE-2026-9769
7.5 HIGH

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively …

Aug 23, 2026
CVE-2026-4671
7.5 HIGH

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based …

Aug 23, 2026
CVE-2026-10053
8.5 HIGH

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain …

Aug 23, 2026
CVE-2026-77115
7.1 HIGH

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.

Aug 23, 2026
CVE-2026-78063
7.4 HIGH

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. The manipulation of the …

Aug 23, 2026
CVE-2026-78062
7.3 HIGH

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the component JWT …

Aug 23, 2026
CVE-2026-78136
7.8 HIGH

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

Aug 23, 2026
CVE-2026-16149
8.8 HIGH

The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exists because the plugin's …

Aug 23, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.