CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50522
9.8 CRITICAL KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49798
9.3 CRITICAL

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49172
9.8 CRITICAL

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-48561
9.6 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-42990
9.8 CRITICAL

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-15701
9.8 CRITICAL

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. …

Jul 14, 2026
CVE-2026-60082
9.1 CRITICAL

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source …

Jul 14, 2026
CVE-2026-58479
9.8 CRITICAL

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers …

Jul 14, 2026
CVE-2026-15265
9.1 CRITICAL

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, …

Jul 14, 2026
CVE-2026-62392
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters …

Jul 14, 2026
CVE-2026-62390
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the …

Jul 14, 2026
CVE-2026-62422
10.0 CRITICAL

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

Jul 14, 2026
CVE-2026-58319
9.1 CRITICAL

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could …

Jul 14, 2026
CVE-2026-56451
10.0 CRITICAL

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web …

Jul 14, 2026
CVE-2026-3014
9.1 CRITICAL

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users …

Jul 14, 2026
CVE-2026-15043
9.8 CRITICAL

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates …

Jul 14, 2026
CVE-2026-59084
9.1 CRITICAL

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from …

Jul 14, 2026
CVE-2026-59083
9.1 CRITICAL

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: …

Jul 14, 2026
CVE-2026-57898
9.0 CRITICAL

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the …

Jul 14, 2026
CVE-2026-11563
9.6 CRITICAL

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization …

Jul 14, 2026
CVE-2026-44761
9.1 CRITICAL

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If …

Jul 14, 2026
CVE-2026-44747
9.9 CRITICAL

SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to …

Jul 14, 2026
CVE-2026-27690
9.1 CRITICAL

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. …

Jul 14, 2026
CVE-2026-58102
9.1 CRITICAL

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via …

Jul 13, 2026
CVE-2026-62327
9.1 CRITICAL

9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts …

Jul 13, 2026
CVE-2026-59801
9.8 CRITICAL

9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any …

Jul 13, 2026
CVE-2026-52533
9.8 CRITICAL

An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file

Jul 13, 2026
CVE-2026-51821
9.8 CRITICAL

SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint

Jul 13, 2026
CVE-2026-51541
9.1 CRITICAL

OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath size. An attacker …

Jul 13, 2026
CVE-2026-51540
9.8 CRITICAL

OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing of …

Jul 13, 2026
CVE-2026-51538
9.1 CRITICAL

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When the server processes critical encapsulation commands, …

Jul 13, 2026
CVE-2026-51537
9.1 CRITICAL

EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing short malformed packets. An attacker can …

Jul 13, 2026
CVE-2026-51536
9.1 CRITICAL

In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed across the call stack. Specifically, …

Jul 13, 2026
CVE-2026-58409
9.1 CRITICAL

ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) on the server by installing …

Jul 13, 2026
CVE-2026-61500
9.8 CRITICAL

Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients …

Jul 13, 2026
CVE-2026-57433
9.8 CRITICAL

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from …

Jul 13, 2026
CVE-2026-13221
9.1 CRITICAL

Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie …

Jul 13, 2026
CVE-2026-61498
9.8 CRITICAL

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying …

Jul 13, 2026
CVE-2026-60121
9.8 CRITICAL

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a …

Jul 13, 2026
CVE-2026-40469
9.1 CRITICAL

Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and …

Jul 13, 2026
CVE-2026-40468
9.1 CRITICAL

Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and …

Jul 13, 2026
CVE-2026-59518
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through <= 8.8.2.

Jul 13, 2026
CVE-2026-59515
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from …

Jul 13, 2026
CVE-2026-57813
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.

Jul 13, 2026
CVE-2026-57811
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX …

Jul 13, 2026
CVE-2026-57770
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

Jul 13, 2026
CVE-2026-57744
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through <= …

Jul 13, 2026
CVE-2026-57739
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This …

Jul 13, 2026
CVE-2026-57738
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1.13.0.

Jul 13, 2026
CVE-2026-57726
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from …

Jul 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.