CVE Find is a real-time vulnerability database indexing 400 878 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2785 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-82039 |
2026-10-02 20h17 +00:00 |
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBu... SQL Injection |
8.8 |
High |
|
CVE-2026-39718 |
2026-10-02 20h17 +00:00 |
Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site R... Cross-Site Request Forgery - CSRF |
8.8 |
High |
|
CVE-2026-104019 |
2026-10-02 20h17 +00:00 |
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution ... OS Command Injection |
9 |
Critical |
|
CVE-2026-96940 |
2026-10-02 19h16 +00:00 |
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileg... |
8.8 |
High |
|
CVE-2026-103956 |
2026-10-02 19h16 +00:00 |
Missing authentication for critical function in the authentication dependency in Loom for AWS before... Authorization problems |
10 |
Critical |
|
CVE-2023-54405 |
2026-10-02 18h36 +00:00 |
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an un... File Inclusion |
9.3 |
Critical |
|
CVE-2026-102795 |
2026-10-02 18h16 +00:00 |
Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic... |
9.3 |
Critical |
|
CVE-2026-104851 |
2026-10-02 17h17 +00:00 |
fsspec is a specification and Python implementation framework for filesystem interfaces. From 0.9.0 ... Code Injection |
8.8 |
High |
|
CVE-2026-104846 |
2026-10-02 16h16 +00:00 |
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap... |
9.8 |
Critical |
|
CVE-2026-103648 |
2026-10-02 16h16 +00:00 |
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to caus... Directory Traversal |
9.1 |
Critical |