CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18577
8.1 HIGH KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Aug 2, 2026
CVE-2026-10848
7.0 HIGH

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and …

Aug 2, 2026
CVE-2026-9856
7.1 HIGH

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of …

Aug 2, 2026
CVE-2026-65321
9.8 CRITICAL

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes …

Aug 2, 2026
CVE-2026-10774
2.4 LOW

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into …

Aug 2, 2026
CVE-2026-68583
5.4 MEDIUM

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator …

Aug 2, 2026
CVE-2026-68582
6.5 MEDIUM

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the …

Aug 2, 2026
CVE-2026-68581
8.1 HIGH

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences …

Aug 2, 2026
CVE-2026-68580
7.5 HIGH

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to …

Aug 2, 2026
CVE-2026-68579
9.6 CRITICAL

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) …

Aug 2, 2026
CVE-2026-68578
7.5 HIGH

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. …

Aug 2, 2026
CVE-2026-67357
7.5 HIGH

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can …

Aug 2, 2026
CVE-2026-67356
8.8 HIGH

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA …

Aug 2, 2026
CVE-2025-71401
5.9 MEDIUM

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to …

Aug 2, 2026
CVE-2025-71400
7.1 HIGH

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys …

Aug 2, 2026
CVE-2025-71399
8.6 HIGH

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, …

Aug 2, 2026
CVE-2026-12231
6.4 MEDIUM

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and …

Aug 2, 2026
CVE-2026-18573
6.5 MEDIUM

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm …

Aug 2, 2026
CVE-2026-18572
6.5 MEDIUM

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A …

Aug 2, 2026
CVE-2026-18571
6.6 MEDIUM

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator …

Aug 2, 2026
CVE-2026-18570
5.4 MEDIUM

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and …

Aug 2, 2026
CVE-2026-16540
7.5 HIGH

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to …

Aug 2, 2026
CVE-2026-16292
5.4 MEDIUM

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to …

Aug 2, 2026
CVE-2026-16291
4.3 MEDIUM

The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such …

Aug 2, 2026
CVE-2026-16285
7.5 HIGH

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download …

Aug 2, 2026
CVE-2026-16273
4.6 MEDIUM

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users …

Aug 2, 2026
CVE-2026-16261
7.5 HIGH

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from …

Aug 2, 2026
CVE-2026-16256
9.8 CRITICAL

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create …

Aug 2, 2026
CVE-2026-16064
5.4 MEDIUM

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking …

Aug 2, 2026
CVE-2026-16063
5.4 MEDIUM

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before …

Aug 2, 2026
CVE-2026-16062
6.6 MEDIUM

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, …

Aug 2, 2026
CVE-2026-16042
4.3 MEDIUM

The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush …

Aug 2, 2026
CVE-2026-15939
2.7 LOW

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front …

Aug 2, 2026
CVE-2026-15385
5.4 MEDIUM

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; …

Aug 2, 2026
CVE-2026-15248
5.5 MEDIUM

The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users …

Aug 2, 2026
CVE-2026-15241
7.5 HIGH

The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated …

Aug 2, 2026
CVE-2026-15236
7.5 HIGH

The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing …

Aug 2, 2026
CVE-2026-15206
7.5 HIGH

The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an …

Aug 2, 2026
CVE-2026-15151
7.5 HIGH

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the …

Aug 2, 2026
CVE-2026-14938
4.3 MEDIUM

The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user …

Aug 2, 2026
CVE-2026-14920
8.2 HIGH

## Summary

Aug 2, 2026
CVE-2026-14864
5.4 MEDIUM

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the …

Aug 2, 2026
CVE-2026-14841
6.1 MEDIUM

The King Addons for Elementor WordPress plugin before 51.1.76 does not escape a user-supplied grid setting before reflecting it into an HTML attribute in an …

Aug 2, 2026
CVE-2026-14817
6.8 MEDIUM

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library …

Aug 2, 2026
CVE-2026-13389
6.5 MEDIUM

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST API routes, allowing unauthenticated attackers to export and delete …

Aug 2, 2026
CVE-2026-12586
8.1 HIGH

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing …

Aug 2, 2026
CVE-2026-11872
4.3 MEDIUM

The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 does not perform a nonce or capability check in an AJAX action that updates …

Aug 2, 2026
CVE-2025-15675
4.8 MEDIUM

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, …

Aug 2, 2026
CVE-2026-9335
6.5 MEDIUM

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` …

Aug 2, 2026
CVE-2026-8457
9.8 CRITICAL

The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to …

Aug 2, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.