CVE Database

60452+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76989
5.3 MEDIUM

A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the file source/src/enet_encap/encap.cc of the component TCP Encapsulation Receive …

Aug 20, 2026
CVE-2026-76988
5.3 MEDIUM

A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forward_open of the file cipconnectionmanager.cc of the component ForwardOpen Handler. Executing a …

Aug 20, 2026
CVE-2026-28163
5.3 MEDIUM

Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through …

Aug 20, 2026
CVE-2026-21784
4.8 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized …

Aug 20, 2026
CVE-2025-62306
5.0 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were …

Aug 20, 2026
CVE-2025-62300
5.9 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable …

Aug 20, 2026
CVE-2025-62299
6.6 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege …

Aug 20, 2026
CVE-2026-73402
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.

Aug 20, 2026
CVE-2026-66647
6.5 MEDIUM

Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.

Aug 20, 2026
CVE-2026-66601
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.

Aug 20, 2026
CVE-2026-66595
5.9 MEDIUM

Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.

Aug 20, 2026
CVE-2026-66586
6.6 MEDIUM

Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

Aug 20, 2026
CVE-2025-62307
5.4 MEDIUM

HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing.

Aug 20, 2026
CVE-2025-53999
6.5 MEDIUM

Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.

Aug 20, 2026
CVE-2026-77067
5.0 MEDIUM

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook …

Aug 20, 2026
CVE-2026-77066
5.0 MEDIUM

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), …

Aug 20, 2026
CVE-2026-73199
6.5 MEDIUM

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight …

Aug 20, 2026
CVE-2026-73196
4.3 MEDIUM

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized …

Aug 20, 2026
CVE-2026-77014
5.3 MEDIUM

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping …

Aug 20, 2026
CVE-2026-14953
4.3 MEDIUM

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.

Aug 20, 2026
CVE-2026-14949
6.5 MEDIUM

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts …

Aug 20, 2026
CVE-2026-71368
6.1 MEDIUM

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operations may be performed.

Aug 20, 2026
CVE-2026-74992
6.8 MEDIUM

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does not …

Aug 20, 2026
CVE-2026-19697
6.8 MEDIUM

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file …

Aug 20, 2026
CVE-2026-19615
6.8 MEDIUM

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allowing users …

Aug 20, 2026
CVE-2026-17153
5.3 MEDIUM

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to …

Aug 20, 2026
CVE-2026-13405
6.6 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is later …

Aug 20, 2026
CVE-2026-76957
4.9 MEDIUM

libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is similar to CVE-2026-50219, CVE-2026-56131 and …

Aug 20, 2026
CVE-2026-76956
5.9 MEDIUM

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, …

Aug 20, 2026
CVE-2026-76800
6.3 MEDIUM

A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Executing a manipulation of the …

Aug 20, 2026
CVE-2026-76799
5.3 MEDIUM

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database …

Aug 20, 2026
CVE-2026-76785
6.3 MEDIUM

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument …

Aug 20, 2026
CVE-2022-4996
5.3 MEDIUM

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point …

Aug 20, 2026
CVE-2026-76929
4.7 MEDIUM

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76927
4.7 MEDIUM

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76924
5.5 MEDIUM

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76923
5.5 MEDIUM

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76922
5.5 MEDIUM

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76921
5.5 MEDIUM

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76920
4.7 MEDIUM

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76919
5.3 MEDIUM

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76918
5.5 MEDIUM

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76917
5.5 MEDIUM

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76889
4.7 MEDIUM

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76883
4.7 MEDIUM

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76882
4.7 MEDIUM

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76881
4.7 MEDIUM

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Aug 19, 2026
CVE-2026-76405
4.3 MEDIUM

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a …

Aug 19, 2026
CVE-2026-76401
5.9 MEDIUM

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp …

Aug 19, 2026
CVE-2026-76400
5.9 MEDIUM

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses …

Aug 19, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.