CVE Find is a real-time vulnerability database indexing 385 546 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2513 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-78657 |
2026-09-02 05h29 +00:00 |
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file delet... Directory Traversal |
9.8 |
Critical |
|
CVE-2024-35585 |
2026-09-02 05h17 +00:00 |
Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.... Authorization problems |
8.6 |
High |
|
CVE-2026-9055 |
2026-09-02 04h26 +00:00 |
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulner... Improper Privilege Management |
9.8 |
Critical |
|
CVE-2026-19754 |
2026-09-02 03h29 +00:00 |
Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileg... SQL Injection |
8.6 |
High |
|
CVE-2026-84715 |
2026-09-02 01h18 +00:00 |
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSu... Authorization problems |
8.7 |
High |
|
CVE-2026-84700 |
2026-09-02 01h17 +00:00 |
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the cl... Authorization problems |
8.6 |
High |
|
CVE-2026-84699 |
2026-09-02 01h17 +00:00 |
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local ac... |
9.1 |
Critical |
|
CVE-2026-84696 |
2026-09-02 01h17 +00:00 |
Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique comm... Authorization problems |
8.2 |
High |
|
CVE-2026-84695 |
2026-09-02 01h17 +00:00 |
BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload ... Cross-site Scripting |
8.7 |
High |
|
CVE-2026-84694 |
2026-09-02 01h17 +00:00 |
Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands exec... OS Command Injection |
8.8 |
High |