CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-52688
7.5 HIGH

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

Jul 23, 2026
CVE-2026-52686
3.7 LOW

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME …

Jul 23, 2026
CVE-2026-52684
3.7 LOW

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does …

Jul 23, 2026
CVE-2026-16723
9.0 CRITICAL

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement …

Jul 23, 2026
CVE-2026-16287
7.8 HIGH

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command …

Jul 23, 2026
CVE-2024-58330
7.5 HIGH

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

Jul 23, 2026
CVE-2024-58023
8.4 HIGH

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

Jul 23, 2026
CVE-2026-9729
6.4 MEDIUM

The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, …

Jul 23, 2026
CVE-2026-9713
7.5 HIGH

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON …

Jul 23, 2026
CVE-2026-9635
6.4 MEDIUM

The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up …

Jul 23, 2026
CVE-2026-59678

An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This …

Jul 23, 2026
CVE-2026-59677

A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in …

Jul 23, 2026
CVE-2026-12421
7.2 HIGH

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to …

Jul 23, 2026
CVE-2026-9577
4.8 MEDIUM

The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page …

Jul 23, 2026
CVE-2026-9066
6.1 MEDIUM

The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it …

Jul 23, 2026
CVE-2026-59676

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain …

Jul 23, 2026
CVE-2026-14291
7.5 HIGH

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker …

Jul 23, 2026
CVE-2026-12082
7.5 HIGH

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify …

Jul 23, 2026
CVE-2026-7534
7.2 HIGH

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and …

Jul 23, 2026
CVE-2026-7232
7.2 HIGH

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due …

Jul 23, 2026
CVE-2026-64600
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an …

Jul 23, 2026
CVE-2026-63226
5.8 MEDIUM

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When …

Jul 23, 2026
CVE-2026-6390
6.8 MEDIUM

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, …

Jul 23, 2026
CVE-2026-7120
5.3 MEDIUM

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including …

Jul 23, 2026
CVE-2026-15074
7.5 HIGH

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of …

Jul 23, 2026
CVE-2026-21723
5.3 MEDIUM

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana …

Jul 23, 2026
CVE-2026-16653
5.3 MEDIUM

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public …

Jul 23, 2026
CVE-2026-16632
7.3 HIGH

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame …

Jul 23, 2026
CVE-2026-16631
5.3 MEDIUM

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The …

Jul 23, 2026
CVE-2026-61246
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60455
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60439
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60373
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60372
9.8 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60371
8.0 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60370
7.5 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60369
9.9 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60368
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60367
9.8 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60366
10.0 CRITICAL

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-38766
7.8 HIGH

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

Jul 22, 2026
CVE-2026-38765
7.8 HIGH

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

Jul 22, 2026
CVE-2026-38763
5.5 MEDIUM

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828

Jul 22, 2026
CVE-2026-16630
5.3 MEDIUM

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to …

Jul 22, 2026
CVE-2026-16629
5.3 MEDIUM

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of the component CLI. Such manipulation …

Jul 22, 2026
CVE-2026-16628
5.3 MEDIUM

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing …

Jul 22, 2026
CVE-2026-64798
9.1 CRITICAL

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random …

Jul 22, 2026
CVE-2026-64797
7.5 HIGH

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. …

Jul 22, 2026
CVE-2026-64796
9.8 CRITICAL

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to …

Jul 22, 2026
CVE-2026-64795
5.4 MEDIUM

Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal …

Jul 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.