CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18599
8.0 HIGH

A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component …

Aug 3, 2026
CVE-2026-18598
8.8 HIGH

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread …

Aug 3, 2026
CVE-2026-21555
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21554
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21553
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21552
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21551
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21550
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21549
7.5 HIGH

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

Aug 3, 2026
CVE-2026-21548
7.5 HIGH

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.

Aug 3, 2026
CVE-2026-4793
7.3 HIGH

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

Aug 3, 2026
CVE-2026-18587
7.5 HIGH

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a manipulation of …

Aug 3, 2026
CVE-2026-16572
8.6 HIGH

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing …

Aug 3, 2026
CVE-2026-16539
8.1 HIGH

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating …

Aug 3, 2026
CVE-2025-15672
8.1 HIGH

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject …

Aug 3, 2026
CVE-2026-20495
7.8 HIGH

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User …

Aug 3, 2026
CVE-2026-20483
7.7 HIGH

In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no …

Aug 3, 2026
CVE-2026-20479
7.5 HIGH

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if …

Aug 3, 2026
CVE-2026-20465
8.1 HIGH

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation …

Aug 3, 2026
CVE-2026-65875
7.1 HIGH

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected …

Aug 3, 2026
CVE-2026-3245
7.5 HIGH

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

Aug 3, 2026
CVE-2026-18577
8.1 HIGH KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Aug 2, 2026
CVE-2026-10848
7.0 HIGH

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and …

Aug 2, 2026
CVE-2026-9856
7.1 HIGH

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of …

Aug 2, 2026
CVE-2026-68581
8.1 HIGH

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences …

Aug 2, 2026
CVE-2026-68580
7.5 HIGH

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to …

Aug 2, 2026
CVE-2026-68578
7.5 HIGH

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. …

Aug 2, 2026
CVE-2026-67357
7.5 HIGH

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can …

Aug 2, 2026
CVE-2026-67356
8.8 HIGH

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA …

Aug 2, 2026
CVE-2025-71400
7.1 HIGH

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys …

Aug 2, 2026
CVE-2025-71399
8.6 HIGH

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, …

Aug 2, 2026
CVE-2026-16540
7.5 HIGH

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to …

Aug 2, 2026
CVE-2026-16285
7.5 HIGH

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download …

Aug 2, 2026
CVE-2026-16261
7.5 HIGH

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from …

Aug 2, 2026
CVE-2026-15241
7.5 HIGH

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated …

Aug 2, 2026
CVE-2026-15236
7.5 HIGH

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing …

Aug 2, 2026
CVE-2026-15206
7.5 HIGH

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an …

Aug 2, 2026
CVE-2026-15151
7.5 HIGH

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the …

Aug 2, 2026
CVE-2026-14920
8.2 HIGH

## Summary

Aug 2, 2026
CVE-2026-12586
8.1 HIGH

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing …

Aug 2, 2026
CVE-2026-18352
7.5 HIGH

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. …

Aug 2, 2026
CVE-2026-13339
7.5 HIGH

The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes …

Aug 2, 2026
CVE-2026-18556
7.4 HIGH KEV

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

Aug 1, 2026
CVE-2026-67352
7.6 HIGH

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS …

Aug 1, 2026
CVE-2026-67343
8.8 HIGH

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in …

Aug 1, 2026
CVE-2026-67336
8.7 HIGH

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. …

Aug 1, 2026
CVE-2026-67333
7.2 HIGH

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the deprecated oidc-provider plugin and the mcp …

Aug 1, 2026
CVE-2026-67331
8.3 HIGH

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' …

Aug 1, 2026
CVE-2026-67329
7.1 HIGH

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscription actions. The middleware validates the …

Aug 1, 2026
CVE-2026-67328
8.1 HIGH

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit …

Aug 1, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.