CVE Database

10684+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14544
9.8 CRITICAL

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to …

Jul 3, 2026
CVE-2026-9079
9.8 CRITICAL

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get …

Jul 3, 2026
CVE-2026-8927
9.1 CRITICAL

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if …

Jul 3, 2026
CVE-2026-8926
9.1 CRITICAL

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like …

Jul 3, 2026
CVE-2026-8925
9.8 CRITICAL

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it …

Jul 3, 2026
CVE-2026-8924
9.1 CRITICAL

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables …

Jul 3, 2026
CVE-2026-11856
9.8 CRITICAL

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one …

Jul 3, 2026
CVE-2026-11564
9.1 CRITICAL

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that …

Jul 3, 2026
CVE-2026-10536
9.8 CRITICAL

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the …

Jul 3, 2026
CVE-2026-9725
9.1 CRITICAL

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 …

Jul 3, 2026
CVE-2026-13768
10.0 CRITICAL

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function which returns …

Jul 3, 2026
CVE-2026-57100
9.9 CRITICAL

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

Jul 2, 2026
CVE-2026-45499
9.9 CRITICAL

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Jul 2, 2026
CVE-2026-41106
9.3 CRITICAL

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Jul 2, 2026
CVE-2026-52830
9.4 CRITICAL

fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a session-file path. The …

Jul 2, 2026
CVE-2026-38971
9.1 CRITICAL

ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().

Jul 2, 2026
CVE-2026-38968
9.8 CRITICAL

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during …

Jul 2, 2026
CVE-2026-59099
9.1 CRITICAL

Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversation state by exploiting AES-GCM initialization vector reuse …

Jul 2, 2026
CVE-2026-58466
9.8 CRITICAL

AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials …

Jul 2, 2026
CVE-2026-44935
9.9 CRITICAL

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 …

Jul 2, 2026
CVE-2024-14037
9.8 CRITICAL

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob …

Jul 2, 2026
CVE-2022-50973
9.8 CRITICAL

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a …

Jul 2, 2026
CVE-2026-58455
9.8 CRITICAL

Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after …

Jul 2, 2026
CVE-2026-56004
10.0 CRITICAL

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a …

Jul 2, 2026
CVE-2026-55116
9.0 CRITICAL

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running …

Jul 2, 2026
CVE-2026-55115
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges …

Jul 2, 2026
CVE-2026-54402
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a …

Jul 2, 2026
CVE-2026-54400
9.1 CRITICAL

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate …

Jul 2, 2026
CVE-2026-50748
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute …

Jul 2, 2026
CVE-2026-50747
9.9 CRITICAL

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application …

Jul 2, 2026
CVE-2026-50746
10.0 CRITICAL

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection …

Jul 2, 2026
CVE-2026-4767
9.8 CRITICAL

Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-ASP: from v1.0.324.900 before v1.4.0.117.

Jul 2, 2026
CVE-2026-5524
9.8 CRITICAL

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including …

Jul 2, 2026
CVE-2026-57683
9.3 CRITICAL

Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.

Jul 2, 2026
CVE-2026-57679
9.3 CRITICAL

Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.

Jul 2, 2026
CVE-2026-57677
9.8 CRITICAL

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

Jul 2, 2026
CVE-2026-57625
9.6 CRITICAL

Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.

Jul 2, 2026
CVE-2026-57624
10.0 CRITICAL

Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

Jul 2, 2026
CVE-2026-57623
9.0 CRITICAL

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

Jul 2, 2026
CVE-2026-57621
9.8 CRITICAL

Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions.

Jul 2, 2026
CVE-2026-27436
9.1 CRITICAL

Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions.

Jul 2, 2026
CVE-2026-27419
9.9 CRITICAL

Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions.

Jul 2, 2026
CVE-2026-14425
9.6 CRITICAL

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 1, 2026
CVE-2026-14424
9.6 CRITICAL

Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 1, 2026
CVE-2026-14423
9.6 CRITICAL

Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Jul 1, 2026
CVE-2026-14420
9.6 CRITICAL

Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via …

Jul 1, 2026
CVE-2026-14419
9.6 CRITICAL

Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 1, 2026
CVE-2026-14417
9.6 CRITICAL

Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML …

Jul 1, 2026
CVE-2026-14416
9.6 CRITICAL

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted …

Jul 1, 2026
CVE-2026-14411
9.6 CRITICAL

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.