CVE Find is a real-time vulnerability database indexing 378 749 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 3539 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-15748 |
2026-08-18 06h16 +00:00 |
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up ... File Inclusion |
9.8 |
Critical |
|
CVE-2026-75094 |
2026-08-18 02h17 +00:00 |
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /... Command InjectionOS Command Injection |
9.1 |
Critical |
|
CVE-2026-9816 |
2026-08-17 22h17 +00:00 |
Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMe... Authorization problems |
8.3 |
High |
|
CVE-2026-71424 |
2026-08-17 22h17 +00:00 |
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers ... Authorization problems |
9.6 |
Critical |
|
CVE-2026-64849 |
2026-08-17 22h17 +00:00 |
MLflow is an open source AI engineering platform for agents, large language models, and machine lear... Server-Side Request Forgery - SSRF |
9.3 |
Critical |
|
CVE-2026-56677 |
2026-08-17 22h17 +00:00 |
9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint i... Authorization problemsServer-Side Request Forgery - SSRF |
8.6 |
High |
|
CVE-2026-75481 |
2026-08-17 21h16 +00:00 |
SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when u... Improper Privilege Management |
8.8 |
High |
|
CVE-2026-75110 |
2026-08-17 21h16 +00:00 |
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is en... |
9.8 |
Critical |
|
CVE-2026-75106 |
2026-08-17 21h16 +00:00 |
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an em... |
9.1 |
Critical |
|
CVE-2026-75103 |
2026-08-17 21h16 +00:00 |
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allow... Authorization problems |
8.8 |
High |