CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82021
8.3 HIGH

Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code …

Aug 28, 2026
CVE-2026-81849
8.8 HIGH

Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand …

Aug 28, 2026
CVE-2026-77586
8.0 HIGH

In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text …

Aug 28, 2026
CVE-2026-75486
8.0 HIGH

Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands …

Aug 28, 2026
CVE-2026-75124
7.5 HIGH

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP …

Aug 28, 2026
CVE-2026-75123
7.2 HIGH

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly …

Aug 28, 2026
CVE-2026-75122
7.2 HIGH

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is …

Aug 28, 2026
CVE-2026-75121
7.2 HIGH

PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a …

Aug 28, 2026
CVE-2026-72984
8.8 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 28, 2026
CVE-2026-56100
8.1 HIGH

SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by …

Aug 28, 2026
CVE-2026-55584
7.5 HIGH

phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP …

Aug 28, 2026
CVE-2026-55552
7.5 HIGH

Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the …

Aug 28, 2026
CVE-2026-55521
8.8 HIGH

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An …

Aug 28, 2026
CVE-2026-55485
8.8 HIGH

Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block …

Aug 28, 2026
CVE-2026-55484
7.5 HIGH

ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a …

Aug 28, 2026
CVE-2026-55215
7.5 HIGH

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is …

Aug 28, 2026
CVE-2026-55108
8.5 HIGH

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader …

Aug 28, 2026
CVE-2026-55066
7.1 HIGH

Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the …

Aug 28, 2026
CVE-2026-55065
8.1 HIGH

Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another …

Aug 28, 2026
CVE-2026-54788
7.5 HIGH

dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value …

Aug 28, 2026
CVE-2026-51659
7.5 HIGH

Incorrect access control in the getUrlFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request …

Aug 28, 2026
CVE-2026-51658
7.5 HIGH

Incorrect access control in the getDmzCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DMZ configuration information via sending a crafted POST request …

Aug 28, 2026
CVE-2026-51650
7.5 HIGH

Incorrect access control in the getRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain remote-management enablement and port information via sending a crafted …

Aug 28, 2026
CVE-2026-51648
7.5 HIGH

Incorrect access control in the getWanInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain WAN information returned by the endpoint via sending a …

Aug 28, 2026
CVE-2026-51647
7.5 HIGH

Incorrect access control in the getCrpcCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a …

Aug 28, 2026
CVE-2026-51644
7.5 HIGH

Incorrect access control in the getCrpcConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud remote-control status and URL information via sending a …

Aug 28, 2026
CVE-2026-51642
7.5 HIGH

Incorrect access control in the getMeshRoutingTable function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh routing information via sending a crafted POST request …

Aug 28, 2026
CVE-2026-51641
7.5 HIGH

Incorrect access control in the getWiFiMeshConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain mesh configuration and runtime state information via sending a …

Aug 28, 2026
CVE-2026-51627
7.5 HIGH

Incorrect access control in the getIptvCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IPTV and IGMP configuration information via sending a crafted …

Aug 28, 2026
CVE-2026-51625
7.5 HIGH

Incorrect access control in the getWiFiEasyCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as SSIDs and Wi-Fi keys, via …

Aug 28, 2026
CVE-2026-51624
7.5 HIGH

Incorrect access control in the getStationMacByIp function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain a client MAC address via sending a crafted POST …

Aug 28, 2026
CVE-2026-51623
7.5 HIGH

Incorrect access control in the getDdnsStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain DDNS runtime status and public IP information via sending …

Aug 28, 2026
CVE-2026-51621
7.5 HIGH

Incorrect access control in the getInitCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive device configuration information via sending a crafted POST …

Aug 28, 2026
CVE-2026-51620
7.5 HIGH

Incorrect access control in the getNetInfoCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain network topology and interface configuration information via sending a …

Aug 28, 2026
CVE-2026-51619
7.5 HIGH

Incorrect access control in the getOnlineClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain online client information via sending a crafted POST request …

Aug 28, 2026
CVE-2026-51618
7.5 HIGH

Incorrect access control in the getWizardCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain setup wizard and onboarding configuration information via sending a …

Aug 28, 2026
CVE-2026-51617
7.5 HIGH

Incorrect access control in the getSysStatusCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain sensitive information such as operation mode, firmware version, serial …

Aug 28, 2026
CVE-2026-51616
7.5 HIGH

Incorrect access control in the getWanIeCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a …

Aug 28, 2026
CVE-2026-51615
7.5 HIGH

Incorrect access control in the getLanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain LAN addressing and DHCP configuration information via sending a …

Aug 28, 2026
CVE-2026-82227
8.5 HIGH

Contributor SQL Injection in WPBulky <= 1.2.2 versions.

Aug 28, 2026
CVE-2026-81767
7.5 HIGH

Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.

Aug 28, 2026
CVE-2026-81760
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.

Aug 28, 2026
CVE-2026-81757
7.2 HIGH

Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.

Aug 28, 2026
CVE-2026-81285
7.5 HIGH

Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versions.

Aug 28, 2026
CVE-2026-81020
7.4 HIGH

wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a …

Aug 28, 2026
CVE-2026-81019
7.4 HIGH

wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a …

Aug 28, 2026
CVE-2026-6176
7.2 HIGH

The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and …

Aug 28, 2026
CVE-2026-5934
7.2 HIGH

The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input …

Aug 28, 2026
CVE-2026-56854
7.5 HIGH

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for …

Aug 28, 2026
CVE-2026-50979
8.1 HIGH

A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the …

Aug 28, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.