CVE Vulnerability Database
Search and browse 377,706 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18597 | HIGH | 8.5 | — | Aug 6, 2026 | The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is re... |
| CVE-2026-0637 | MEDIUM | 4.4 | 0.1% | Aug 6, 2026 | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert... |
| CVE-2025-15039 | CRITICAL | 9.4 | 0.4% | Aug 6, 2026 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require... |
| CVE-2025-14779 | LOW | 3.8 | 0.2% | Aug 6, 2026 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet... |
| CVE-2025-13909 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT... |
| CVE-2025-13736 | LOW | 3.7 | 0.2% | Aug 6, 2026 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo... |
| CVE-2025-13394 | MEDIUM | 5.4 | 0.1% | Aug 6, 2026 | The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque... |
| CVE-2025-12627 | LOW | 2.4 | 0.1% | Aug 6, 2026 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated... |
| CVE-2025-11850 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us... |
| CVE-2024-8995 | MEDIUM | 4.9 | 0.1% | Aug 6, 2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a... |
| CVE-2024-6832 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not mainta... |
| CVE-2024-10302 | MEDIUM | 5.8 | 0.2% | Aug 6, 2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allo... |
| CVE-2023-7355 | — | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. |
| CVE-2023-7354 | — | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. |
| CVE-2023-7353 | — | — | — | Aug 6, 2026 | Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned. |
| CVE-2026-19007 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedEle... |
| CVE-2026-19006 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tool... |
| CVE-2026-19005 | MEDIUM | 6.3 | 0.2% | Aug 6, 2026 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file s... |
| CVE-2026-18967 | HIGH | 8.1 | 0.1% | Aug 6, 2026 | A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured a... |
| CVE-2026-18510 | HIGH | 7.2 | 0.2% | Aug 6, 2026 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross... |
| CVE-2026-18400 | MEDIUM | 6.4 | 0.3% | Aug 6, 2026 | The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Store... |
| CVE-2026-18395 | MEDIUM | 5.4 | — | Aug 6, 2026 | The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before o... |
| CVE-2026-18050 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves tem... |
| CVE-2026-16954 | MEDIUM | 6.5 | 0.2% | Aug 6, 2026 | The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admi... |
| CVE-2026-16734 | HIGH | 7.5 | 0.1% | Aug 6, 2026 | The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe p... |
