CVE Vulnerability Database
Search and browse 375,585 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15045 | MEDIUM | 6.5 | — | Aug 12, 2026 | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against... |
| CVE-2026-11325 | HIGH | 8.8 | — | Aug 12, 2026 | Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, ... |
| CVE-2026-68868 | — | — | — | Aug 12, 2026 | The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re... |
| CVE-2026-67284 | MEDIUM | 5.3 | — | Aug 12, 2026 | Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authentica... |
| CVE-2026-64955 | MEDIUM | 6.1 | — | Aug 12, 2026 | When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CS... |
| CVE-2026-64952 | MEDIUM | 6.5 | — | Aug 12, 2026 | The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLL... |
| CVE-2026-64951 | LOW | 3.5 | — | Aug 12, 2026 | A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic... |
| CVE-2026-18663 | MEDIUM | 5.9 | — | Aug 12, 2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Sess... |
| CVE-2026-18652 | MEDIUM | 4.9 | — | Aug 12, 2026 | Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within... |
| CVE-2026-67283 | MEDIUM | 6.9 | — | Aug 12, 2026 | Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenti... |
| CVE-2026-67282 | CRITICAL | 10 | — | Aug 12, 2026 | Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker ... |
| CVE-2026-19566 | — | — | — | Aug 12, 2026 | Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix ... |
| CVE-2026-19426 | HIGH | 8.8 | — | Aug 12, 2026 | POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directl... |
| CVE-2025-41771 | MEDIUM | 5.3 | — | Aug 12, 2026 | An authenticated attacker with low privileges can access an endpoint in the controller’s web interface that is vulnerabl... |
| CVE-2025-41770 | HIGH | 7.5 | — | Aug 12, 2026 | An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an rem... |
| CVE-2025-41769 | CRITICAL | 9.8 | — | Aug 12, 2026 | The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. A... |
| CVE-2026-66659 | CRITICAL | 9.3 | — | Aug 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome ... |
| CVE-2026-19594 | HIGH | 8.1 | — | Aug 12, 2026 | Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-dep... |
| CVE-2026-19217 | — | — | — | Aug 12, 2026 | The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTM... |
| CVE-2026-19073 | MEDIUM | 5.3 | — | Aug 12, 2026 | The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o... |
| CVE-2026-19052 | MEDIUM | 4.3 | — | Aug 12, 2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not perform capability checks on two administrative AJAX ac... |
| CVE-2026-19050 | MEDIUM | 6.4 | — | Aug 12, 2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the ca... |
| CVE-2026-18962 | MEDIUM | 4.3 | — | Aug 12, 2026 | The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload int... |
| CVE-2026-18943 | MEDIUM | 6.5 | — | Aug 12, 2026 | The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow... |
| CVE-2026-18789 | HIGH | 7.5 | — | Aug 12, 2026 | The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, ... |
