CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-57724
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

Jul 13, 2026
CVE-2026-57719
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= …

Jul 13, 2026
CVE-2026-57714
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from …

Jul 13, 2026
CVE-2026-57710
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a …

Jul 13, 2026
CVE-2026-57707
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects …

Jul 13, 2026
CVE-2026-57702
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects …

Jul 13, 2026
CVE-2026-57401
9.9 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a …

Jul 13, 2026
CVE-2026-41041
9.1 CRITICAL

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade …

Jul 13, 2026
CVE-2026-14453
9.6 CRITICAL

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without …

Jul 13, 2026
CVE-2026-57830
9.1 CRITICAL

The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion.

Jul 13, 2026
CVE-2026-4769
9.8 CRITICAL

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented …

Jul 13, 2026
CVE-2026-11964
9.1 CRITICAL

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated …

Jul 13, 2026
CVE-2026-15511
9.8 CRITICAL

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the …

Jul 12, 2026
CVE-2026-56271
9.8 CRITICAL

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in …

Jul 12, 2026
CVE-2026-56260
9.1 CRITICAL

Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths …

Jul 12, 2026
CVE-2026-61447
10.0 CRITICAL

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers …

Jul 11, 2026
CVE-2026-61445
9.9 CRITICAL

PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM …

Jul 11, 2026
CVE-2026-60090
9.8 CRITICAL

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are …

Jul 11, 2026
CVE-2026-57827
9.8 CRITICAL

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Jul 11, 2026
CVE-2026-20744
9.8 CRITICAL

The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.

Jul 10, 2026
CVE-2026-15089
9.1 CRITICAL

vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.

Jul 10, 2026
CVE-2026-14480
9.9 CRITICAL

OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly …

Jul 10, 2026
CVE-2026-11913
9.8 CRITICAL

vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.

Jul 10, 2026
CVE-2026-12535
9.8 CRITICAL

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

Jul 10, 2026
CVE-2026-10768
9.8 CRITICAL

Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.

Jul 10, 2026
CVE-2026-9726
9.8 CRITICAL

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 …

Jul 10, 2026
CVE-2026-57807
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Client) allows Password …

Jul 10, 2026
CVE-2026-55879
9.3 CRITICAL

OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any …

Jul 10, 2026
CVE-2026-12761
9.8 CRITICAL

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up …

Jul 10, 2026
CVE-2026-57158
9.1 CRITICAL

FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for …

Jul 10, 2026
CVE-2026-57156
9.8 CRITICAL

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in …

Jul 10, 2026
CVE-2026-61459
9.8 CRITICAL

MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check …

Jul 10, 2026
CVE-2026-5801
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP allows Command Line …

Jul 10, 2026
CVE-2026-59151
9.6 CRITICAL

Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when deciding which tenant …

Jul 10, 2026
CVE-2026-2397
9.8 CRITICAL

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue …

Jul 10, 2026
CVE-2026-51119
9.1 CRITICAL

An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components

Jul 10, 2026
CVE-2026-55500
9.9 CRITICAL

9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, …

Jul 10, 2026
CVE-2026-15143
9.3 CRITICAL

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) …

Jul 10, 2026
CVE-2026-61444
9.1 CRITICAL

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can …

Jul 10, 2026
CVE-2026-59792
9.6 CRITICAL

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

Jul 10, 2026
CVE-2026-56765
9.8 CRITICAL

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. …

Jul 10, 2026
CVE-2026-56688
9.1 CRITICAL

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high …

Jul 10, 2026
CVE-2026-15378
9.3 CRITICAL

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a …

Jul 10, 2026
CVE-2026-40008
9.8 CRITICAL

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qualified Java class name …

Jul 10, 2026
CVE-2026-40005
9.1 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process …

Jul 10, 2026
CVE-2026-28564
9.8 CRITICAL

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 …

Jul 10, 2026
CVE-2026-15300
9.1 CRITICAL

The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, …

Jul 10, 2026
CVE-2026-15282
9.8 CRITICAL

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions …

Jul 10, 2026
CVE-2026-14894
9.8 CRITICAL

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, …

Jul 10, 2026
CVE-2026-54769
10.0 CRITICAL

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) …

Jul 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.