CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16745
8.8 HIGH

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within …

Jul 23, 2026
CVE-2026-65757
8.1 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data …

Jul 23, 2026
CVE-2026-65755
7.5 HIGH

Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded …

Jul 23, 2026
CVE-2026-65754
7.5 HIGH

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

Jul 23, 2026
CVE-2026-65430
7.5 HIGH

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.

Jul 23, 2026
CVE-2026-64876
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, …

Jul 23, 2026
CVE-2026-64799
7.5 HIGH

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or …

Jul 23, 2026
CVE-2026-15017
8.8 HIGH

The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing …

Jul 23, 2026
CVE-2026-52688
7.5 HIGH

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

Jul 23, 2026
CVE-2026-16287
7.8 HIGH

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command …

Jul 23, 2026
CVE-2024-58330
7.5 HIGH

A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

Jul 23, 2026
CVE-2024-58023
8.4 HIGH

Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

Jul 23, 2026
CVE-2026-9713
7.5 HIGH

The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON …

Jul 23, 2026
CVE-2026-12421
7.2 HIGH

The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to …

Jul 23, 2026
CVE-2026-14291
7.5 HIGH

The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker …

Jul 23, 2026
CVE-2026-12082
7.5 HIGH

The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify …

Jul 23, 2026
CVE-2026-7534
7.2 HIGH

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and …

Jul 23, 2026
CVE-2026-7232
7.2 HIGH

The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due …

Jul 23, 2026
CVE-2026-64600
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an …

Jul 23, 2026
CVE-2026-15074
7.5 HIGH

@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of …

Jul 23, 2026
CVE-2026-16632
7.3 HIGH

A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame …

Jul 23, 2026
CVE-2026-61246
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60455
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60439
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60373
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60371
8.0 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60370
7.5 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-60368
8.8 HIGH

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and …

Jul 22, 2026
CVE-2026-38766
7.8 HIGH

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function

Jul 22, 2026
CVE-2026-38765
7.8 HIGH

An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

Jul 22, 2026
CVE-2026-64797
7.5 HIGH

Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. …

Jul 22, 2026
CVE-2026-64792
7.5 HIGH

Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content …

Jul 22, 2026
CVE-2026-64791
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not …

Jul 22, 2026
CVE-2026-63685
8.8 HIGH

Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and …

Jul 22, 2026
CVE-2026-63684
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor …

Jul 22, 2026
CVE-2026-63683
7.5 HIGH

Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote …

Jul 22, 2026
CVE-2026-63280
8.8 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens …

Jul 22, 2026
CVE-2026-63265
8.0 HIGH

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints …

Jul 22, 2026
CVE-2026-13089
7.5 HIGH

OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify. When the caller does not pin …

Jul 22, 2026
CVE-2025-60835
7.8 HIGH

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

Jul 22, 2026
CVE-2025-50330
8.8 HIGH

An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.

Jul 22, 2026
CVE-2025-50327
8.8 HIGH

An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the …

Jul 22, 2026
CVE-2025-50324
8.8 HIGH

An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.

Jul 22, 2026
CVE-2025-44090
8.8 HIGH

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Jul 22, 2026
CVE-2025-44089
8.8 HIGH

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

Jul 22, 2026
CVE-2026-64829
7.4 HIGH

Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password …

Jul 22, 2026
CVE-2026-14899
7.5 HIGH

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, …

Jul 22, 2026
CVE-2026-14881
7.8 HIGH

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it …

Jul 22, 2026
CVE-2026-13078
7.7 HIGH

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read …

Jul 22, 2026
CVE-2026-13077
7.1 HIGH

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The …

Jul 22, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.