CVE Database

48241+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-30046
7.5 HIGH

A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE …

Aug 27, 2026
CVE-2026-30045
7.5 HIGH

An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET …

Aug 27, 2026
CVE-2026-26899
8.8 HIGH

An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands …

Aug 27, 2026
CVE-2026-26459
7.5 HIGH

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data.

Aug 27, 2026
CVE-2026-26457
7.5 HIGH

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_dump_msg() function when processing COAP messages containing options with zero length.

Aug 27, 2026
CVE-2026-26456
7.5 HIGH

A null pointer dereference vulnerability exists in the server-side session management logic of ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5. The issue is caused by a race condition between the …

Aug 27, 2026
CVE-2026-26453
7.5 HIGH

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the …

Aug 27, 2026
CVE-2026-26452
7.5 HIGH

ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers.

Aug 27, 2026
CVE-2026-19889
8.2 HIGH

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, …

Aug 27, 2026
CVE-2026-66155
7.6 HIGH

A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions …

Aug 27, 2026
CVE-2026-81625
8.8 HIGH

A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer …

Aug 27, 2026
CVE-2026-81581
8.8 HIGH

Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside …

Aug 27, 2026
CVE-2026-81579
8.8 HIGH

In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a …

Aug 27, 2026
CVE-2026-81576
7.7 HIGH

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole …

Aug 27, 2026
CVE-2026-81575
7.5 HIGH

If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data …

Aug 27, 2026
CVE-2026-81574
8.2 HIGH

In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format …

Aug 27, 2026
CVE-2026-81573
8.6 HIGH

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only …

Aug 27, 2026
CVE-2026-81572
7.8 HIGH

In CodeMeter Runtime from version 8.40 to (excluding) 8.41a and 9.00 to (excluding) 9.10, cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. …

Aug 27, 2026
CVE-2026-81277
8.5 HIGH

Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions.

Aug 27, 2026
CVE-2026-81273
8.1 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions.

Aug 27, 2026
CVE-2026-81271
8.8 HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.

Aug 27, 2026
CVE-2026-80433
7.5 HIGH

Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.

Aug 27, 2026
CVE-2026-78293
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions.

Aug 27, 2026
CVE-2026-78289
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in CozyStay <= 1.10.0 versions.

Aug 27, 2026
CVE-2026-78285
8.5 HIGH

Subscriber SQL Injection in Like Button Rating <= 2.6.61 versions.

Aug 27, 2026
CVE-2026-78283
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.

Aug 27, 2026
CVE-2026-78281
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.

Aug 27, 2026
CVE-2026-78276
7.2 HIGH

Editor PHP Object Injection in Fluent Boards Pro <= 2.0.11 versions.

Aug 27, 2026
CVE-2026-78271
7.2 HIGH

Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

Aug 27, 2026
CVE-2026-78261
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Realtyna Organic IDX plugin <= 5.4.1 versions.

Aug 27, 2026
CVE-2026-78257
8.8 HIGH

Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.

Aug 27, 2026
CVE-2026-75020
8.1 HIGH

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache APISIX. A caller who holds valid credentials for one entry …

Aug 27, 2026
CVE-2026-75005
7.5 HIGH

Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an extended period in graphql-limit-count …

Aug 27, 2026
CVE-2026-74848
7.5 HIGH

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache APISIX. An attacker could make other clients receive attacker-chosen or other users' responses on …

Aug 27, 2026
CVE-2026-32564
8.5 HIGH

Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

Aug 27, 2026
CVE-2026-32550
8.5 HIGH

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

Aug 27, 2026
CVE-2026-27330
8.6 HIGH

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

Aug 27, 2026
CVE-2026-78333
8.8 HIGH

The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its …

Aug 27, 2026
CVE-2026-78137
7.5 HIGH

The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a …

Aug 27, 2026
CVE-2026-77018
8.8 HIGH

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently …

Aug 27, 2026
CVE-2026-77017
7.7 HIGH

The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed …

Aug 27, 2026
CVE-2026-47893
7.5 HIGH

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 …

Aug 27, 2026
CVE-2026-47889
7.5 HIGH

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework …

Aug 27, 2026
CVE-2026-47888
7.5 HIGH

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 …

Aug 27, 2026
CVE-2026-47886
7.5 HIGH

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is …

Aug 27, 2026
CVE-2026-47885
7.5 HIGH

The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 …

Aug 27, 2026
CVE-2026-47879
7.7 HIGH

Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - …

Aug 27, 2026
CVE-2026-47877
8.2 HIGH

Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6

Aug 27, 2026
CVE-2026-47849
7.1 HIGH

Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 …

Aug 27, 2026
CVE-2026-19715
7.5 HIGH

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is …

Aug 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.