CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10526
5.8 MEDIUM

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site …

Aug 4, 2026
CVE-2026-68744
3.3 LOW

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the …

Aug 4, 2026
CVE-2026-18739
2.5 LOW

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application …

Aug 4, 2026
CVE-2026-18569
3.7 LOW

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component …

Aug 4, 2026
CVE-2026-16881

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally …

Aug 4, 2026
CVE-2026-42169
7.3 HIGH

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading …

Aug 4, 2026
CVE-2026-18723
6.3 MEDIUM

A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey …

Aug 4, 2026
CVE-2026-18722
6.3 MEDIUM

A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. …

Aug 4, 2026
CVE-2026-18721
4.3 MEDIUM

A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO …

Aug 4, 2026
CVE-2026-14818
7.2 HIGH

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, …

Aug 4, 2026
CVE-2026-8508
6.5 MEDIUM

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass …

Aug 4, 2026
CVE-2026-6837
7.2 HIGH

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges …

Aug 4, 2026
CVE-2026-18720
5.3 MEDIUM

A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. …

Aug 4, 2026
CVE-2026-17614
4.4 MEDIUM

A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file …

Aug 4, 2026
CVE-2026-18719
6.3 MEDIUM

A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of …

Aug 4, 2026
CVE-2026-58045
6.2 MEDIUM

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. …

Aug 4, 2026
CVE-2026-58044
3.7 LOW

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while …

Aug 4, 2026
CVE-2026-58042
5.9 MEDIUM

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this …

Aug 4, 2026
CVE-2026-58041
5.3 MEDIUM

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and …

Aug 4, 2026
CVE-2026-56846
7.5 HIGH

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and …

Aug 4, 2026
CVE-2026-56845
7.5 HIGH

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an …

Aug 4, 2026
CVE-2026-66326
6.5 MEDIUM

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66325
6.1 MEDIUM

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-66322
7.1 HIGH

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-66321
7.4 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66318
8.1 HIGH

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-66317
5.4 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

Aug 4, 2026
CVE-2026-66316
5.4 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-66315
7.5 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66314
6.5 MEDIUM

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-66313
6.8 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 4, 2026
CVE-2026-66312
6.5 MEDIUM

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66311
6.2 MEDIUM

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 4, 2026
CVE-2026-66310
7.7 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Aug 4, 2026
CVE-2026-65804
6.1 MEDIUM

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-65802
7.4 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-62870
8.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-18686
9.8 CRITICAL

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web …

Aug 4, 2026
CVE-2026-18685
9.8 CRITICAL

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. …

Aug 4, 2026
CVE-2026-11836

Insufficient verification of data authenticity in Caliptra Core ROM and Core Firmware (validate_debug_unlock_token()) in subsystem mode allows an attacker with access to the integrator's debug …

Aug 4, 2026
CVE-2026-11835

Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mode allows a compromised local attacker to silently bypass …

Aug 4, 2026
CVE-2026-67978
7.5 HIGH

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN …

Aug 3, 2026
CVE-2026-67673
4.6 MEDIUM

A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where …

Aug 3, 2026
CVE-2026-48399
7.5 HIGH

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could …

Aug 3, 2026
CVE-2026-48333
9.8 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain …

Aug 3, 2026
CVE-2026-48331
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not …

Aug 3, 2026
CVE-2026-48330
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Aug 3, 2026
CVE-2026-48326
9.9 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Aug 3, 2026
CVE-2026-48323
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code …

Aug 3, 2026
CVE-2026-48317
9.6 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.