CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-58571
8.8 HIGH

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root …

Sep 1, 2026
CVE-2026-51766
7.5 HIGH

Incorrect access control in the setDevReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reboot the local device and, on a master, fan out …

Sep 1, 2026
CVE-2026-19513
8.1 HIGH

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient …

Sep 1, 2026
CVE-2024-14047
7.2 HIGH

A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with …

Sep 1, 2026
CVE-2026-84145
7.5 HIGH

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another …

Sep 1, 2026
CVE-2026-84131
8.8 HIGH

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR …

Sep 1, 2026
CVE-2026-84128
8.8 HIGH

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Sep 1, 2026
CVE-2026-84123
8.8 HIGH

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Sep 1, 2026
CVE-2026-84117
8.8 HIGH

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

Sep 1, 2026
CVE-2026-79683
8.8 HIGH

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary …

Sep 1, 2026
CVE-2026-58575
8.8 HIGH

Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.

Sep 1, 2026
CVE-2026-84199
7.7 HIGH

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, …

Sep 1, 2026
CVE-2026-84196
7.7 HIGH

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through …

Sep 1, 2026
CVE-2026-84195
7.7 HIGH

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate …

Sep 1, 2026
CVE-2026-84192
7.1 HIGH

LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls …

Sep 1, 2026
CVE-2026-84190
7.2 HIGH

LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. …

Sep 1, 2026
CVE-2026-84189
8.1 HIGH

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page …

Sep 1, 2026
CVE-2026-84187
8.2 HIGH

AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with …

Sep 1, 2026
CVE-2026-83595
8.1 HIGH

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers …

Sep 1, 2026
CVE-2026-76111
8.8 HIGH

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege …

Sep 1, 2026
CVE-2026-84059
7.4 HIGH

A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. …

Sep 1, 2026
CVE-2026-59681
8.8 HIGH

A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured …

Sep 1, 2026
CVE-2026-59680
8.0 HIGH

An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and …

Sep 1, 2026
CVE-2026-25706
7.5 HIGH

Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree …

Sep 1, 2026
CVE-2026-19914
7.2 HIGH

The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due …

Sep 1, 2026
CVE-2026-75921
7.2 HIGH

The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to …

Sep 1, 2026
CVE-2026-19952
7.5 HIGH

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in …

Sep 1, 2026
CVE-2026-19806
8.8 HIGH

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator …

Sep 1, 2026
CVE-2026-19796
7.2 HIGH

The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter in all versions up …

Sep 1, 2026
CVE-2026-19573
7.2 HIGH

The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, 1.10.2 …

Sep 1, 2026
CVE-2026-82957
7.3 HIGH

A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook …

Aug 31, 2026
CVE-2026-82922
7.3 HIGH

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of …

Aug 31, 2026
CVE-2026-82921
7.3 HIGH

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the …

Aug 31, 2026
CVE-2026-82882
8.8 HIGH

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated …

Aug 31, 2026
CVE-2026-82397
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. …

Aug 31, 2026
CVE-2026-82393
7.5 HIGH

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts …

Aug 31, 2026
CVE-2026-77348
8.2 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php …

Aug 31, 2026
CVE-2026-83596
8.8 HIGH

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

Aug 31, 2026
CVE-2026-82919
7.3 HIGH

A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component …

Aug 31, 2026
CVE-2026-82914
7.3 HIGH

A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact …

Aug 31, 2026
CVE-2026-82908
8.8 HIGH

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the …

Aug 31, 2026
CVE-2026-82392
7.1 HIGH

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name …

Aug 31, 2026
CVE-2026-82229
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.

Aug 31, 2026
CVE-2026-82228
8.1 HIGH

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

Aug 31, 2026
CVE-2026-82225
7.4 HIGH

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

Aug 31, 2026
CVE-2026-82224
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.

Aug 31, 2026
CVE-2026-82221
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

Aug 31, 2026
CVE-2026-81892
8.1 HIGH

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single …

Aug 31, 2026
CVE-2026-81891
8.1 HIGH

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the …

Aug 31, 2026
CVE-2026-81889
8.6 HIGH

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.