CVE Find is a real-time vulnerability database indexing 382 178 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 3550 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-78555 |
2026-08-24 19h38 +00:00 |
RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administ... |
9.4 |
Critical |
|
CVE-2026-40877 |
2026-08-24 19h16 +00:00 |
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP ob... Code Injection |
8.7 |
High |
|
CVE-2026-30864 |
2026-08-24 19h16 +00:00 |
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflec... Cross-site Scripting |
8.9 |
High |
|
CVE-2026-76838 |
2026-08-24 18h17 +00:00 |
Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInter... Server-Side Request Forgery - SSRF |
8.5 |
High |
|
CVE-2026-76836 |
2026-08-24 18h17 +00:00 |
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not requi... Code InjectionAuthorization problems |
8.8 |
High |
|
CVE-2026-76835 |
2026-08-24 18h17 +00:00 |
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk... |
9.1 |
Critical |
|
CVE-2026-76073 |
2026-08-24 18h17 +00:00 |
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. An... Authorization problems |
8.8 |
High |
|
CVE-2026-71933 |
2026-08-24 18h17 +00:00 |
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo... Authorization problems |
9.1 |
Critical |
|
CVE-2026-71921 |
2026-08-24 18h17 +00:00 |
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in ... OS Command Injection |
9.8 |
Critical |
|
CVE-2026-71914 |
2026-08-24 18h17 +00:00 |
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component.... OS Command Injection |
9.8 |
Critical |