CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18574

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access …

Aug 3, 2026
CVE-2026-69082

CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoint accepted HTTP GET requests for an operation that modified …

Aug 3, 2026
CVE-2026-69079

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a …

Aug 3, 2026
CVE-2026-69078

CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI content, including conversion names, descriptions, and comments, is …

Aug 3, 2026
CVE-2026-68742
5.5 MEDIUM

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. …

Aug 3, 2026
CVE-2026-33591

A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unauthenticated attacker to bypass security restriction using a specially crafted packet and retrieve a …

Aug 3, 2026
CVE-2026-0392

eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrity-protected. On each launch …

Aug 3, 2026
CVE-2026-69075

FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, recurring-case information, user profile …

Aug 3, 2026
CVE-2026-63563
6.5 MEDIUM

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When …

Aug 3, 2026
CVE-2026-63545
2.4 LOW

Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.

Aug 3, 2026
CVE-2026-62416
5.3 MEDIUM

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the …

Aug 3, 2026
CVE-2026-60011
5.3 MEDIUM

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

Aug 3, 2026
CVE-2026-8794

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform username enumeration by measuring …

Aug 3, 2026
CVE-2026-8793

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to perform unrestricted brute-force …

Aug 3, 2026
CVE-2026-28147
5.4 MEDIUM

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects …

Aug 3, 2026
CVE-2026-21555
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21554
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21553
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21552
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21551
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21550
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21549
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21548
7.5 HIGH

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.

Aug 3, 2026
CVE-2026-18593
5.6 MEDIUM

A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management …

Aug 3, 2026
CVE-2026-18592
4.7 MEDIUM

A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email …

Aug 3, 2026
CVE-2026-18591
2.1 LOW

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component …

Aug 3, 2026
CVE-2026-18590
6.3 MEDIUM

A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation …

Aug 3, 2026
CVE-2026-12259
5.3 MEDIUM

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them before enforcing SHA-256 or MD5 checksum validation. This …

Aug 3, 2026
CVE-2026-9593
6.7 MEDIUM

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing …

Aug 3, 2026
CVE-2026-4793
7.3 HIGH

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

Aug 3, 2026
CVE-2026-18589
9.8 CRITICAL

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of the argument User1Passwd results in …

Aug 3, 2026
CVE-2026-18588
9.8 CRITICAL

A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the argument CONTENT_LENGTH leads …

Aug 3, 2026
CVE-2026-18587
7.5 HIGH

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of …

Aug 3, 2026
CVE-2026-16572
8.6 HIGH

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing …

Aug 3, 2026
CVE-2026-16565
4.3 MEDIUM

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify product ownership on its product-attribute REST write endpoints, allowing users …

Aug 3, 2026
CVE-2026-16564
4.3 MEDIUM

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.9 does not verify order ownership on a REST endpoint that performs bulk order-status …

Aug 3, 2026
CVE-2026-16563
6.5 MEDIUM

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through its REST API, …

Aug 3, 2026
CVE-2026-16539
8.1 HIGH

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating …

Aug 3, 2026
CVE-2026-16534
9.1 CRITICAL

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a …

Aug 3, 2026
CVE-2026-16532
9.1 CRITICAL

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated …

Aug 3, 2026
CVE-2026-16300
9.8 CRITICAL

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including …

Aug 3, 2026
CVE-2026-16297
4.1 MEDIUM

The Clearfy Cache WordPress plugin before 2.4.3 does not restrict the classes allowed when unserializing settings-import data, allowing users with administrator access to perform PHP …

Aug 3, 2026
CVE-2026-16289
4.3 MEDIUM

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks when listing a group's pending membership requests, allowing any authenticated user such as a …

Aug 3, 2026
CVE-2026-16276
2.7 LOW

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users …

Aug 3, 2026
CVE-2026-16274
2.7 LOW

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing …

Aug 3, 2026
CVE-2026-16250
9.8 CRITICAL

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowing unauthenticated users …

Aug 3, 2026
CVE-2026-16060
9.8 CRITICAL

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, relying on a bypassable …

Aug 3, 2026
CVE-2026-16057
6.5 MEDIUM

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by …

Aug 3, 2026
CVE-2026-15931
6.1 MEDIUM

The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval request, nor escape it when …

Aug 3, 2026
CVE-2026-15930
9.4 CRITICAL

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value as a user ID …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.