CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81768
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.

Aug 31, 2026
CVE-2026-81765
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.

Aug 31, 2026
CVE-2026-81764
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.

Aug 31, 2026
CVE-2026-81298
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.

Aug 31, 2026
CVE-2026-81297
7.5 HIGH

Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Aug 31, 2026
CVE-2026-81296
7.5 HIGH

Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

Aug 31, 2026
CVE-2026-81291
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

Aug 31, 2026
CVE-2026-81290
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.

Aug 31, 2026
CVE-2026-81287
8.5 HIGH

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

Aug 31, 2026
CVE-2026-79407
7.5 HIGH

A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() …

Aug 31, 2026
CVE-2026-75458
8.1 HIGH

The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID …

Aug 31, 2026
CVE-2026-61641
8.1 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an …

Aug 31, 2026
CVE-2026-54598
7.5 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any …

Aug 31, 2026
CVE-2026-51735
7.5 HIGH

Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request …

Aug 31, 2026
CVE-2026-13732
7.8 HIGH

A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that …

Aug 31, 2026
CVE-2026-83497
8.8 HIGH

Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to …

Aug 31, 2026
CVE-2026-72001
8.1 HIGH

Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the …

Aug 31, 2026
CVE-2026-53553
7.7 HIGH

Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File …

Aug 31, 2026
CVE-2026-82815
7.3 HIGH

A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This …

Aug 31, 2026
CVE-2026-79750
7.7 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, …

Aug 31, 2026
CVE-2026-79747
7.1 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, …

Aug 31, 2026
CVE-2026-79746
8.1 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, …

Aug 31, 2026
CVE-2026-79745
7.1 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, …

Aug 31, 2026
CVE-2026-79744
8.8 HIGH

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, …

Aug 31, 2026
CVE-2026-82808
7.3 HIGH

A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the …

Aug 31, 2026
CVE-2026-17615
7.5 HIGH

A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated attacker to perform an unauthenticated remote file read. By sending a specially crafted …

Aug 31, 2026
CVE-2026-82807
8.8 HIGH

A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. …

Aug 31, 2026
CVE-2026-77966
8.8 HIGH

The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions …

Aug 31, 2026
CVE-2026-75133
7.5 HIGH

Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump …

Aug 31, 2026
CVE-2026-51719
7.5 HIGH

Incorrect access control in the delUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove URL filtering rules via sending a crafted POST request …

Aug 31, 2026
CVE-2026-51716
7.5 HIGH

Incorrect access control in the delPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to delete port-forwarding rules via sending a crafted POST request to …

Aug 31, 2026
CVE-2026-82801
7.3 HIGH

A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. …

Aug 31, 2026
CVE-2026-82701
7.3 HIGH

A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component …

Aug 31, 2026
CVE-2026-66047
8.1 HIGH

ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to install and activate arbitrary plugins by brute-forcing …

Aug 31, 2026
CVE-2026-51695
7.5 HIGH

Incorrect access control in the setDdnsCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter dynamic DNS state via sending a crafted POST request …

Aug 31, 2026
CVE-2026-51694
7.5 HIGH

Incorrect access control in the setStaticDhcpRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to add or change static DHCP rules via sending a crafted …

Aug 31, 2026
CVE-2026-82217
8.8 HIGH

In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and state helpers) …

Aug 31, 2026
CVE-2026-76763
7.5 HIGH

A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An …

Aug 31, 2026
CVE-2026-51673
7.5 HIGH

Incorrect access control in the setNtpCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter time synchronization settings via sending a crafted POST request …

Aug 31, 2026
CVE-2026-51671
7.5 HIGH

Incorrect access control in the getCloudDownloadStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware download state information via sending a crafted …

Aug 31, 2026
CVE-2026-51668
7.5 HIGH

Incorrect access control in the setLanguageCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify language configuration via sending a crafted POST request to …

Aug 31, 2026
CVE-2026-19702
7.8 HIGH

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows …

Aug 31, 2026
CVE-2026-19616
7.5 HIGH

Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2.

Aug 31, 2026
CVE-2026-5956
8.8 HIGH

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Ankara Hosting Site Management Panel allows SQL Injection. This issue affects …

Aug 31, 2026
CVE-2026-12894
8.8 HIGH

A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic content like HTML pages or emails. The issue …

Aug 31, 2026
CVE-2026-71257
7.5 HIGH

Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request …

Aug 31, 2026
CVE-2026-82880
7.5 HIGH

YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG, FreeMind, and OpenSearch parsers that fail to disable external entity resolution. …

Aug 31, 2026
CVE-2026-82876
8.2 HIGH

Phison PS3111-S11 controller firmware verifies RSA signatures using a public modulus embedded within the firmware image itself rather than anchored in immutable storage. Attackers can …

Aug 31, 2026
CVE-2026-82680
8.8 HIGH

A weakness has been identified in D-Link DSM-G600 1.01. This affects an unknown function of the file /load_file.cgi of the component Multipart Handler. Executing a …

Aug 31, 2026
CVE-2026-19873
7.5 HIGH

HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. When a Repeatable element …

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.