CVE Database

10419+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-63732
9.9 CRITICAL

9router 0.4.59 (fixed in 0.4.60) contains a chain of vulnerabilities: a hardcoded default password (123456) that authenticates any fresh installation, a bypass of the LOCAL_ONLY …

Jul 23, 2026
CVE-2025-71389
10.0 CRITICAL

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling …

Jul 23, 2026
CVE-2024-58354
9.9 CRITICAL

cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger …

Jul 23, 2026
CVE-2026-52439
9.8 CRITICAL

An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism

Jul 23, 2026
CVE-2026-47724
9.9 CRITICAL

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token …

Jul 23, 2026
CVE-2026-15981
9.8 CRITICAL

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This …

Jul 23, 2026
CVE-2026-15630
9.9 CRITICAL

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch …

Jul 23, 2026
CVE-2026-63359
9.8 CRITICAL

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access …

Jul 23, 2026
CVE-2026-6516
10.0 CRITICAL

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Jul 23, 2026
CVE-2026-65701
9.1 CRITICAL

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read …

Jul 23, 2026
CVE-2026-65700
9.8 CRITICAL

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files …

Jul 23, 2026
CVE-2026-47752
9.9 CRITICAL

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification …

Jul 23, 2026
CVE-2026-47668
10.0 CRITICAL

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the …

Jul 23, 2026
CVE-2026-15617
9.1 CRITICAL

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via case- or Unicode-different identities.

Jul 23, 2026
CVE-2026-15616
9.1 CRITICAL

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized access.

Jul 23, 2026
CVE-2026-15612
9.1 CRITICAL

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session-binding.

Jul 23, 2026
CVE-2026-15611
9.1 CRITICAL

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized …

Jul 23, 2026
CVE-2026-65689
9.8 CRITICAL

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary …

Jul 23, 2026
CVE-2026-65688
9.8 CRITICAL

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attackers to read arbitrary …

Jul 23, 2026
CVE-2026-65687
9.8 CRITICAL

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary …

Jul 23, 2026
CVE-2026-65907
9.1 CRITICAL

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

Jul 23, 2026
CVE-2026-65606
9.6 CRITICAL

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an installed …

Jul 23, 2026
CVE-2026-65605
9.6 CRITICAL

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/template …

Jul 23, 2026
CVE-2026-65471
9.6 CRITICAL

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

Jul 23, 2026
CVE-2026-65461
9.1 CRITICAL

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

Jul 23, 2026
CVE-2026-65455
9.1 CRITICAL

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

Jul 23, 2026
CVE-2026-64813
10.0 CRITICAL

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Jul 23, 2026
CVE-2026-64812
10.0 CRITICAL

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Jul 23, 2026
CVE-2026-61951
9.8 CRITICAL

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

Jul 23, 2026
CVE-2026-61950
9.3 CRITICAL

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

Jul 23, 2026
CVE-2026-61949
9.3 CRITICAL

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

Jul 23, 2026
CVE-2026-61948
9.3 CRITICAL

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

Jul 23, 2026
CVE-2026-59555
10.0 CRITICAL

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

Jul 23, 2026
CVE-2026-59544
9.8 CRITICAL

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

Jul 23, 2026
CVE-2026-59543
9.9 CRITICAL

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

Jul 23, 2026
CVE-2026-59540
9.8 CRITICAL

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

Jul 23, 2026
CVE-2026-59526
9.3 CRITICAL

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

Jul 23, 2026
CVE-2026-59525
9.3 CRITICAL

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

Jul 23, 2026
CVE-2026-59514
9.3 CRITICAL

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

Jul 23, 2026
CVE-2026-57784
9.6 CRITICAL

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Jul 23, 2026
CVE-2026-27064
9.1 CRITICAL

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

Jul 23, 2026
CVE-2026-65431
9.8 CRITICAL

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe …

Jul 23, 2026
CVE-2026-64874
9.8 CRITICAL

Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

Jul 23, 2026
CVE-2026-64873
9.8 CRITICAL

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

Jul 23, 2026
CVE-2026-15015
9.8 CRITICAL

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is …

Jul 23, 2026
CVE-2026-15011
9.8 CRITICAL

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and …

Jul 23, 2026
CVE-2026-14282
9.8 CRITICAL

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary …

Jul 23, 2026
CVE-2026-16723
9.0 CRITICAL

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement …

Jul 23, 2026
CVE-2026-60372
9.8 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60369
9.9 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.