CVE Find is a real-time vulnerability database indexing 367 786 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2639 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-39878 |
2026-07-20 18h16 +00:00 |
Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the ... Cross-site Scripting |
9.3 |
Critical |
|
CVE-2026-8170 |
2026-07-20 17h34 +00:00 |
The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to saf... |
8.7 |
High |
|
CVE-2026-54051 |
2026-07-20 17h17 +00:00 |
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandb... OS Command Injection |
9.9 |
Critical |
|
CVE-2026-44178 |
2026-07-20 17h17 +00:00 |
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vu... |
8.8 |
High |
|
CVE-2026-41521 |
2026-07-20 17h17 +00:00 |
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerabili... |
8.2 |
High |
|
CVE-2026-41252 |
2026-07-20 17h17 +00:00 |
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp,... |
9.8 |
Critical |
|
CVE-2026-35048 |
2026-07-20 17h17 +00:00 |
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configurati... |
9.8 |
Critical |
|
CVE-2026-63429 |
2026-07-20 16h17 +00:00 |
HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authe... Authorization problemsFile Inclusion |
8.6 |
High |
|
CVE-2026-51027 |
2026-07-20 16h17 +00:00 |
An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2... |
9.9 |
Critical |
|
CVE-2026-46415 |
2026-07-20 16h17 +00:00 |
The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate request... |
8.2 |
High |