CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-14872
6.8 MEDIUM

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in …

Aug 4, 2026
CVE-2026-14848
5.4 MEDIUM

The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription checkout belongs to the current user, …

Aug 4, 2026
CVE-2026-14824
4.8 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outputting it into an unquoted HTML attribute, …

Aug 4, 2026
CVE-2026-14816
6.5 MEDIUM

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices …

Aug 4, 2026
CVE-2026-12698
4.3 MEDIUM

The wpForo Forum WordPress plugin before 3.1.3 does not restrict which profile fields a member may set when editing their own account, allowing users with …

Aug 4, 2026
CVE-2026-10526
5.8 MEDIUM

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoints, allowing unauthenticated attackers to induce the site …

Aug 4, 2026
CVE-2026-18723
6.3 MEDIUM

A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-survey-status.do of the component Survey …

Aug 4, 2026
CVE-2026-18722
6.3 MEDIUM

A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey/app/v6/dw-design-survey/dev-survey.do of the component Survey Handler. …

Aug 4, 2026
CVE-2026-18721
4.3 MEDIUM

A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO …

Aug 4, 2026
CVE-2026-8508
6.5 MEDIUM

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN to bypass …

Aug 4, 2026
CVE-2026-18720
5.3 MEDIUM

A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. …

Aug 4, 2026
CVE-2026-17614
4.4 MEDIUM

A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getConfigurationFile() methods in wildfly-core/deployment-repository do not validate that the resolved file …

Aug 4, 2026
CVE-2026-18719
6.3 MEDIUM

A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a manipulation of …

Aug 4, 2026
CVE-2026-58045
6.2 MEDIUM

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire process to crash. …

Aug 4, 2026
CVE-2026-58042
5.9 MEDIUM

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this …

Aug 4, 2026
CVE-2026-58041
5.3 MEDIUM

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and …

Aug 4, 2026
CVE-2026-66326
6.5 MEDIUM

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66325
6.1 MEDIUM

Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-66317
5.4 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network.

Aug 4, 2026
CVE-2026-66316
5.4 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-66314
6.5 MEDIUM

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-66313
6.8 MEDIUM

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 4, 2026
CVE-2026-66312
6.5 MEDIUM

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66311
6.2 MEDIUM

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.

Aug 4, 2026
CVE-2026-65804
6.1 MEDIUM

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-67673
4.6 MEDIUM

A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where …

Aug 3, 2026
CVE-2026-67617
4.8 MEDIUM

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that allows admin-authenticated attackers to inject arbitrary JavaScript by submitting …

Aug 3, 2026
CVE-2026-67616
4.3 MEDIUM

Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create …

Aug 3, 2026
CVE-2026-69245
6.5 MEDIUM

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes …

Aug 3, 2026
CVE-2026-52520
5.4 MEDIUM

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript …

Aug 3, 2026
CVE-2026-49132
5.4 MEDIUM

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate …

Aug 3, 2026
CVE-2026-49131
5.4 MEDIUM

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by …

Aug 3, 2026
CVE-2026-48061
5.9 MEDIUM

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the …

Aug 3, 2026
CVE-2026-18738
4.7 MEDIUM

Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by …

Aug 3, 2026
CVE-2026-18737
6.5 MEDIUM

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value …

Aug 3, 2026
CVE-2026-18736
5.0 MEDIUM

Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying …

Aug 3, 2026
CVE-2026-18648
5.3 MEDIUM

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the …

Aug 3, 2026
CVE-2026-18646
5.3 MEDIUM

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component Author Name …

Aug 3, 2026
CVE-2026-18645
5.4 MEDIUM

A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin …

Aug 3, 2026
CVE-2026-58139
6.5 MEDIUM

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS …

Aug 3, 2026
CVE-2026-18655
6.5 MEDIUM

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated …

Aug 3, 2026
CVE-2026-18654
6.8 MEDIUM

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow …

Aug 3, 2026
CVE-2026-18644
5.4 MEDIUM

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the component …

Aug 3, 2026
CVE-2026-18632
6.3 MEDIUM

A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component …

Aug 3, 2026
CVE-2026-18631
6.3 MEDIUM

A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/src/main/java/com/jeequan/jeepay/mgr/ctrl/sysuser/SysLogController.java of the component PreAuthorize Handler. …

Aug 3, 2026
CVE-2026-38446
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title …

Aug 3, 2026
CVE-2026-38444
6.1 MEDIUM

osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored …

Aug 3, 2026
CVE-2026-40717
6.6 MEDIUM

Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially …

Aug 3, 2026
CVE-2026-69153
5.3 MEDIUM

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior …

Aug 3, 2026
CVE-2026-68930
6.5 MEDIUM

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were never opened …

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.