CVE Database

10419+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-70553
9.8 CRITICAL

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted …

Aug 4, 2026
CVE-2026-70552
9.8 CRITICAL

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any …

Aug 4, 2026
CVE-2026-69703
9.8 CRITICAL

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw …

Aug 4, 2026
CVE-2026-49435
9.8 CRITICAL

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code …

Aug 4, 2026
CVE-2026-0163
9.8 CRITICAL

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of …

Aug 4, 2026
CVE-2017-20242
9.8 CRITICAL

Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or …

Aug 4, 2026
CVE-2017-20241
9.8 CRITICAL

Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or …

Aug 4, 2026
CVE-2026-24254
9.8 CRITICAL

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this …

Aug 4, 2026
CVE-2026-63456
9.8 CRITICAL

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access …

Aug 4, 2026
CVE-2026-63455
9.8 CRITICAL

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access …

Aug 4, 2026
CVE-2025-29296
9.8 CRITICAL

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C …

Aug 4, 2026
CVE-2026-69110
9.1 CRITICAL

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by …

Aug 4, 2026
CVE-2026-69098
9.8 CRITICAL

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON …

Aug 4, 2026
CVE-2026-25289
9.6 CRITICAL

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

Aug 4, 2026
CVE-2026-61515
9.8 CRITICAL

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by …

Aug 4, 2026
CVE-2026-61514
9.8 CRITICAL

Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets …

Aug 4, 2026
CVE-2026-15721
9.8 CRITICAL

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital …

Aug 4, 2026
CVE-2026-14804
9.1 CRITICAL

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This …

Aug 4, 2026
CVE-2026-14175
9.8 CRITICAL

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to …

Aug 4, 2026
CVE-2026-18754
9.1 CRITICAL

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows …

Aug 4, 2026
CVE-2026-18753
9.1 CRITICAL

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows …

Aug 4, 2026
CVE-2026-16618
9.8 CRITICAL

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the …

Aug 4, 2026
CVE-2026-15958
9.3 CRITICAL

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers …

Aug 4, 2026
CVE-2026-18686
9.8 CRITICAL

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web …

Aug 4, 2026
CVE-2026-18685
9.8 CRITICAL

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. …

Aug 4, 2026
CVE-2026-48333
9.8 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain …

Aug 3, 2026
CVE-2026-48331
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not …

Aug 3, 2026
CVE-2026-48330
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Aug 3, 2026
CVE-2026-48326
9.9 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in …

Aug 3, 2026
CVE-2026-48323
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code …

Aug 3, 2026
CVE-2026-48317
9.6 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code …

Aug 3, 2026
CVE-2026-18684
9.8 CRITICAL

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. …

Aug 3, 2026
CVE-2026-18667
9.6 CRITICAL

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to …

Aug 3, 2026
CVE-2026-69240
9.8 CRITICAL

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function …

Aug 3, 2026
CVE-2026-68980
9.1 CRITICAL

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against …

Aug 3, 2026
CVE-2026-68979
9.8 CRITICAL

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating …

Aug 3, 2026
CVE-2026-48031
9.1 CRITICAL

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded …

Aug 3, 2026
CVE-2026-38447
9.8 CRITICAL

osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current …

Aug 3, 2026
CVE-2026-18616
9.8 CRITICAL

A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so …

Aug 3, 2026
CVE-2026-18615
9.8 CRITICAL

A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so …

Aug 3, 2026
CVE-2026-18614
9.8 CRITICAL

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. …

Aug 3, 2026
CVE-2026-18613
9.8 CRITICAL

A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so …

Aug 3, 2026
CVE-2026-18612
9.8 CRITICAL

A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so …

Aug 3, 2026
CVE-2026-41452
9.8 CRITICAL

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending …

Aug 3, 2026
CVE-2026-39932
9.1 CRITICAL

OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that allows authenticated administrators to execute arbitrary operating system …

Aug 3, 2026
CVE-2026-18602
9.8 CRITICAL

A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. …

Aug 3, 2026
CVE-2026-18248
9.1 CRITICAL

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications are documented to use for authorization decisions such as reading API …

Aug 3, 2026
CVE-2026-9487
9.1 CRITICAL

XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node …

Aug 3, 2026
CVE-2026-9390
9.1 CRITICAL

XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value …

Aug 3, 2026
CVE-2026-69085
10.0 CRITICAL

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.