CVE Database

4751+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18839
2.2 LOW

An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who …

Aug 5, 2026
CVE-2026-70600
3.1 LOW

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, the native autofill popup …

Aug 5, 2026
CVE-2026-70598
3.9 LOW

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.0, 41.2.1, and 42.0.0-beta.3, offscreen rendering frame data …

Aug 5, 2026
CVE-2026-12730
3.8 LOW

IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 007, and 24.0.0 through 24.0.0 Interim …

Aug 5, 2026
CVE-2026-8029
3.9 LOW

The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db …

Aug 5, 2026
CVE-2026-16993
3.7 LOW

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an …

Aug 5, 2026
CVE-2025-15677
3.5 LOW

The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category setting before outputting it back in an admin page, allowing high-privilege users …

Aug 5, 2026
CVE-2026-18852
3.3 LOW

A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. …

Aug 5, 2026
CVE-2026-18817
2.2 LOW

A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the …

Aug 4, 2026
CVE-2026-70483
3.1 LOW

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether …

Aug 4, 2026
CVE-2026-16791
3.9 LOW

A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite …

Aug 4, 2026
CVE-2026-18790
3.3 LOW

A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequest Handler. …

Aug 4, 2026
CVE-2026-16070
2.7 LOW

The Brizy WordPress plugin before 2.8.19 does not properly verify authorization on the object being modified before updating a template's type meta, validating a request …

Aug 4, 2026
CVE-2026-16068
3.5 LOW

The Brizy WordPress plugin before 2.8.19 does not properly restrict who can modify its site-global design data and does not sanitise part of that data …

Aug 4, 2026
CVE-2026-11366
3.7 LOW

The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthenticated AJAX actions: when the MonsterInsights WordPress plugin before …

Aug 4, 2026
CVE-2026-68744
3.3 LOW

A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the …

Aug 4, 2026
CVE-2026-18739
2.5 LOW

A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application …

Aug 4, 2026
CVE-2026-18569
3.7 LOW

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Build of Keycloak. This component …

Aug 4, 2026
CVE-2026-58044
3.7 LOW

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while …

Aug 4, 2026
CVE-2026-18682
3.1 LOW

A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload …

Aug 3, 2026
CVE-2026-56608
3.7 LOW

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level …

Aug 3, 2026
CVE-2026-63545
2.4 LOW

Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.

Aug 3, 2026
CVE-2026-18591
2.1 LOW

A vulnerability was identified in Meesho Online Shopping App up to 20260607 on Android. Affected by this vulnerability is an unknown functionality of the component …

Aug 3, 2026
CVE-2026-16276
2.7 LOW

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability check on an AJAX action that returns aggregated store revenue totals, allowing users …

Aug 3, 2026
CVE-2026-16274
2.7 LOW

The Classified Listing WordPress plugin before 5.4.4 does not perform a capability or ownership check on an AJAX action that returns a post's content, allowing …

Aug 3, 2026
CVE-2026-15231
2.7 LOW

The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing …

Aug 3, 2026
CVE-2026-18581
3.3 LOW

A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja …

Aug 3, 2026
CVE-2026-10774
2.4 LOW

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into …

Aug 2, 2026
CVE-2026-15939
2.7 LOW

The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front …

Aug 2, 2026
CVE-2026-67334
3.8 LOW

better-auth versions before 1.6.11 fail to delete cached sessions when removing users via admin, anonymous, or SCIM endpoints when secondaryStorage is configured and storeSessionInDatabase is …

Aug 1, 2026
CVE-2026-66401
2.1 LOW

FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID …

Aug 1, 2026
CVE-2026-14823
2.2 LOW

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify authorization on some of its seating actions, allowing users with contributor-level access …

Aug 1, 2026
CVE-2026-14214
2.7 LOW

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.4 does not restrict which fields can be written through its customer import, allowing a …

Aug 1, 2026
CVE-2026-14197
3.8 LOW

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to …

Aug 1, 2026
CVE-2026-14195
2.7 LOW

The Brizy WordPress plugin before 2.8.18 does not properly verify authorization on a request handler before returning post content, allowing users with the Contributor role …

Aug 1, 2026
CVE-2026-11882
3.7 LOW

The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes to the initiating user session, allowing …

Aug 1, 2026
CVE-2026-10827
3.5 LOW

The Spectra Legacy WordPress plugin before 2.20.0 does not validate or escape several block style attributes before using them to build the CSS it outputs …

Aug 1, 2026
CVE-2026-54787
3.1 LOW

sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.1, sigstore-go does not check a bundle signing timestamp against the validity window …

Jul 31, 2026
CVE-2026-55825
3.1 LOW

Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an authenticated backend user who can access one job can request an attachment identifier …

Jul 31, 2026
CVE-2026-57232
3.1 LOW

Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end module passes configured RSS feed URLs …

Jul 31, 2026
CVE-2026-55824
2.6 LOW

Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth credentials to external hosts. Contao's crawler …

Jul 31, 2026
CVE-2026-25552
3.7 LOW

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a …

Jul 31, 2026
CVE-2026-56571
3.7 LOW

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and …

Jul 31, 2026
CVE-2026-56570
3.7 LOW

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers …

Jul 31, 2026
CVE-2026-56568
3.7 LOW

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead …

Jul 31, 2026
CVE-2026-18217
3.4 LOW

A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs when Keycloak handles SAML …

Jul 31, 2026
CVE-2026-18209
3.4 LOW

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed …

Jul 31, 2026
CVE-2026-18206
3.7 LOW

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services. The issue occurs when a realm administrator uses …

Jul 31, 2026
CVE-2026-15381
3.7 LOW

The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated …

Jul 31, 2026
CVE-2026-14927
3.7 LOW

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed …

Jul 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.