CVE & CISA-KEV Catalog

384,676 CVEs1,686 actively exploited (KEV)
Active:
  • CVSS 6.3 v3·EPSS -·No fix yet

    A vulnerability was detected in sambitraj Student Management System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is the function mysqli_query of the file student_dashboard.php of the component Student Dashboard. The manipulation of the argument roll_no results in improper authorization. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

    Published 2026-08-30

  • CVSS 5.0 v3·EPSS -·No fix yet

    A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is possible. The attack is considered to have high complexity. The exploitation is known to be difficult. The project was informed of the problem early through an issue report but has not responded yet.

    Published 2026-08-30

  • CVSS 7.2 v3·EPSS 0.4%·No fix yet

    Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.

    Published 2026-08-27

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

    Published 2026-08-27

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

    Published 2026-08-25

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

    Published 2026-08-24

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.

    Published 2026-08-24

  • CVSS 7.2 v3·EPSS 0.3%·No fix yet

    HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.

    Published 2026-08-24

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

    Published 2026-08-24

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

    Published 2026-08-24

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

    Published 2026-08-24

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely.

    Published 2026-08-24

  • CVSS 5.4 v3·EPSS 0.3%·No fix yet

    A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of the argument id/username leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published 2026-08-23

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to improper authorization. The attack can be launched remotely.

    Published 2026-08-21

  • CVSS 5.4 v3·EPSS 0.3%·No fix yet

    A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This manipulation of the argument ID causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 24.0.0 is able to mitigate this issue. Patch name: b2a2c995537cb6282383b5e903cb5ffa29b823e6. The affected component should be upgraded.

    Published 2026-08-21

  • CVSS 6.5 v3·EPSS 0.4%·No fix yet

    Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.

    Published 2026-08-20

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published 2026-08-20

  • CVSS 6.3 v3·EPSS 0.3%·No fix yet

    A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.

    Published 2026-08-20

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

    Published 2026-08-20

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

    Published 2026-08-20

  • CVSS 9.6 v3·EPSS 0.2%·Fix available

    A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is possible by impersonating a client name in the Ticket Granting Service (TGS) due to FreeIPA services not verifying Privilege Attribute Certificate (PAC) certificates. This vulnerability could allow an authenticated Active Directory user to escalate their privileges within the FreeIPA domain.

    Published 2026-08-20

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

    Published 2026-08-19

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

    Published 2026-08-19

  • CVSS 6.3 v3·EPSS 0.3%·No fix yet

    A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. The affected element is the function DataSourceController.add of the file DataSourceController.java of the component QueryerFactory. Such manipulation of the argument queryerClass leads to permission issues. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published 2026-08-19

  • CVSS 7.8 v3·EPSS 0.2%·No fix yet

    Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an explicit local satp.MODE validity check at the use site

    Published 2026-08-18

  • CVSS 8.2 v3·EPSS 0.4%·No fix yet

    Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.

    Published 2026-08-18

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions.

    Published 2026-08-18

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.

    Published 2026-08-18

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Product Supplier Edit Controller. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. Upgrading to version 0.9.3 is able to resolve this issue. This patch is called f767ac1a5987d4865d9f158c6a967680f8e45468. It is suggested to upgrade the affected component.

    Published 2026-08-18

  • CVSS 7.9 v3·EPSS 0.5%·Fix available

    A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these excessive permissions. This could lead to full cluster administrator privileges through the creation of new ClusterRoleBindings or the disclosure of sensitive information by accessing all secrets across the cluster.

    Published 2026-08-17

  • CVSS 4.3 v3·EPSS 0.3%·No fix yet

    A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

    Published 2026-08-17

  • CVSS 5.4 v3·EPSS 0.2%·No fix yet

    A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

    Published 2026-08-17

  • CVSS 6.3 v3·EPSS 0.3%·No fix yet

    A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended.

    Published 2026-08-16

  • CVSS 6.3 v3·EPSS 0.2%·No fix yet

    A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Management Interface. The manipulation leads to improper access controls. The attack can only be initiated within the local network. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published 2026-08-16

  • CVSS 3.1 v3·EPSS 0.3%·No fix yet

    A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorrect default permissions. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult.

    Published 2026-08-15

  • CVSS 3.1 v3·EPSS 0.2%·No fix yet

    A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitability is considered difficult. This vulnerability only affects products that are no longer supported by the maintainer.

    Published 2026-08-14

  • CVSS 3.8 v3·EPSS 0.3%·No fix yet

    A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

    Published 2026-08-14

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access scope, and the new key's scopes are read directly from the request body with no subset check. An attacker holding a minimal-scope API key on a super account can submit an empty scopes array to mint an unscoped, full-access super key, bypassing scope restrictions (and enabling further chains such as configuration write to RCE).

    Published 2026-08-14

  • CVSS 8.8 v3·EPSS 0.3%·No fix yet

    OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root within one minute.

    Published 2026-08-13

  • CVSS 9.8 v3·EPSS 0.4%·No fix yet

    filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.

    Published 2026-08-13

  • CVSS 5.4 v3·EPSS 0.2%·No fix yet

    Gitea LFS Deploy-Key Privilege Escalation

    Published 2026-08-13

  • CVSS 7.7 v3·EPSS 0.3%·No fix yet

    Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions.

    Published 2026-08-13

  • CVSS 9.8 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

    Published 2026-08-13

  • CVSS 8.8 v3·EPSS 0.4%·No fix yet

    Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.

    Published 2026-08-13

  • CVSS 8.1 v3·EPSS 0.3%·No fix yet

    Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions.

    Published 2026-08-13

  • CVSS 3.3 v3·EPSS 0.2%·Fix available

    GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed a user with a pending membership to receive permissions granted by a custom role, due to incorrect privilege assignment that did not account for membership state.

    Published 2026-08-12

  • CVSS 9.3 v4·EPSS 0.3%·No fix yet

    Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.

    Published 2026-08-12

  • CVSS 5.3 v3·EPSS 0.3%·Fix available

    A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authenticated users to gain unauthorized access to remote managed hub search results, leading to information disclosure.

    Published 2026-08-11

  • CVSS 7.6 v3·EPSS 0.4%·Fix available

    A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a malicious Argo Workflow through the V1 API path. This allows the API server to create pods with elevated privileges, acting as a 'confused deputy' on behalf of the attacker. Successful exploitation grants the attacker node-root access, enabling arbitrary code execution and full control over the underlying node.

    Published 2026-08-10

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.