CVE Database

10953+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-83524
9.9 CRITICAL

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the …

Aug 31, 2026
CVE-2026-82971
10.0 CRITICAL

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of …

Aug 31, 2026
CVE-2026-82954
9.9 CRITICAL

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation …

Aug 31, 2026
CVE-2026-82226
9.8 CRITICAL

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

Aug 31, 2026
CVE-2026-81780
10.0 CRITICAL

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

Aug 31, 2026
CVE-2026-81779
10.0 CRITICAL

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through …

Aug 31, 2026
CVE-2026-81763
9.3 CRITICAL

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

Aug 31, 2026
CVE-2026-81756
9.3 CRITICAL

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

Aug 31, 2026
CVE-2026-81293
9.3 CRITICAL

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

Aug 31, 2026
CVE-2026-53552
9.6 CRITICAL

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row …

Aug 31, 2026
CVE-2026-79748
9.9 CRITICAL

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, …

Aug 31, 2026
CVE-2026-51730
9.1 CRITICAL

Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request …

Aug 31, 2026
CVE-2026-51725
9.1 CRITICAL

Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request …

Aug 31, 2026
CVE-2026-51720
9.1 CRITICAL

Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request …

Aug 31, 2026
CVE-2026-76133
9.8 CRITICAL

The affected Ebyte product uses a deprecated hashing algorithm in an authentication-related operation. Under conditions where an attacker can manipulate or predict the authentication exchange, …

Aug 31, 2026
CVE-2026-73819
9.8 CRITICAL

The affected Ebyte product's vendor configuration utility permits access to administrative functions without verifying the operator's identity under certain credential conditions. An unauthenticated attacker on …

Aug 31, 2026
CVE-2026-82970
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. …

Aug 31, 2026
CVE-2026-59111
9.3 CRITICAL

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an …

Aug 31, 2026
CVE-2026-51681
9.1 CRITICAL

Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to …

Aug 31, 2026
CVE-2026-51680
9.1 CRITICAL

Incorrect access control in the setLedCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to modify LED behavior via sending a crafted POST request to …

Aug 31, 2026
CVE-2026-51679
9.1 CRITICAL

Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request …

Aug 31, 2026
CVE-2026-82695
10.0 CRITICAL

A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The …

Aug 31, 2026
CVE-2026-82694
10.0 CRITICAL

A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation …

Aug 31, 2026
CVE-2026-82693
10.0 CRITICAL

A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a …

Aug 31, 2026
CVE-2026-82692
9.9 CRITICAL

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of …

Aug 31, 2026
CVE-2026-82691
9.1 CRITICAL

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the …

Aug 31, 2026
CVE-2026-82690
9.1 CRITICAL

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. …

Aug 31, 2026
CVE-2026-82689
9.9 CRITICAL

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the …

Aug 31, 2026
CVE-2026-82688
9.1 CRITICAL

A security vulnerability has been detected in D-Link DNS-340L and DNS-345 1.01B04/1.03B06/1.04.B02/1.05b04. This impacts an unknown function of the file /cgi-bin/virtual_vol.cgi of the component Virtual …

Aug 31, 2026
CVE-2026-49003
9.6 CRITICAL

Attackers can exploit command injection vulnerabilities to delete core system runtime files, causing the monitoring module to crash and become paralyzed; simultaneously, they can obtain …

Aug 31, 2026
CVE-2026-82874
9.9 CRITICAL

ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder …

Aug 31, 2026
CVE-2026-82872
9.1 CRITICAL

ToolJet before v3.16.208 fails to validate that the path organizationId matches the authenticated user's workspace before performing ToolJet DB table operations. A workspace admin can …

Aug 31, 2026
CVE-2026-82870
9.6 CRITICAL

ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in …

Aug 31, 2026
CVE-2026-82860
9.8 CRITICAL

@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that …

Aug 31, 2026
CVE-2026-82859
9.8 CRITICAL

hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting …

Aug 31, 2026
CVE-2026-82858
9.8 CRITICAL

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply …

Aug 31, 2026
CVE-2026-82857
9.8 CRITICAL

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient …

Aug 31, 2026
CVE-2026-82856
9.8 CRITICAL

@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide …

Aug 31, 2026
CVE-2026-82855
9.8 CRITICAL

@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant …

Aug 31, 2026
CVE-2026-82854
9.8 CRITICAL

Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size …

Aug 31, 2026
CVE-2026-58574
9.8 CRITICAL

Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this …

Aug 31, 2026
CVE-2026-82616
9.9 CRITICAL

A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in …

Aug 31, 2026
CVE-2026-82593
9.9 CRITICAL

A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. …

Aug 31, 2026
CVE-2026-82592
9.9 CRITICAL

A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The …

Aug 30, 2026
CVE-2026-82542
10.0 CRITICAL

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa …

Aug 30, 2026
CVE-2026-82539
9.1 CRITICAL

A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation …

Aug 30, 2026
CVE-2026-15980
9.8 CRITICAL

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization …

Aug 30, 2026
CVE-2026-15369
9.8 CRITICAL

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due …

Aug 29, 2026
CVE-2026-82460
9.8 CRITICAL

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use …

Aug 29, 2026
CVE-2026-82456
10.0 CRITICAL

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can …

Aug 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.