CVE Find is a real-time vulnerability database indexing 361 478 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 1938 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-12415 |
2026-06-27 05h16 +00:00 |
The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing ca... Improper Privilege Management |
9.8 |
Critical |
|
CVE-2026-28701 |
2026-06-26 22h40 +00:00 |
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated rem... Directory Traversal |
9.3 |
Critical |
|
CVE-2026-55069 |
2026-06-26 22h16 +00:00 |
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability e... |
8.7 |
High |
|
CVE-2026-53576 |
2026-06-26 22h16 +00:00 |
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authe... Code Injection |
10 |
Critical |
|
CVE-2026-49869 |
2026-06-26 22h16 +00:00 |
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, Authentic... OS Command InjectionAuthorization problemsServer-Side Request Forgery - SSRF |
10 |
Critical |
|
CVE-2026-54353 |
2026-06-26 21h16 +00:00 |
Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation p... Server-Side Request Forgery - SSRF |
8.5 |
High |
|
CVE-2026-54352 |
2026-06-26 21h16 +00:00 |
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packag... Directory Traversal |
9.6 |
Critical |
|
CVE-2026-54351 |
2026-06-26 21h16 +00:00 |
Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budib... |
8.2 |
High |
|
CVE-2026-54350 |
2026-06-26 21h16 +00:00 |
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any p... SQL Injection |
10 |
Critical |
|
CVE-2026-55188 |
2026-06-26 20h17 +00:00 |
RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, ... Authorization problems |
8.2 |
High |