CVE Find is a real-time vulnerability database indexing 372 515 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 2092 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-65321 |
2026-08-02 14h56 +00:00 |
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attacker... SQL Injection |
9.3 |
Critical |
|
CVE-2026-68579 |
2026-08-02 13h16 +00:00 |
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard cli... Overflow |
9.6 |
Critical |
|
CVE-2026-67356 |
2026-08-02 13h16 +00:00 |
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with Hos... Improper Privilege Management |
8.8 |
High |
|
CVE-2025-71399 |
2026-08-02 13h16 +00:00 |
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3,... |
8.6 |
High |
|
CVE-2026-8457 |
2026-08-02 00h16 +00:00 |
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all ve... |
9.8 |
Critical |
|
CVE-2026-55735 |
2026-08-01 18h46 +00:00 |
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated att... |
8.2 |
High |
|
CVE-2026-67343 |
2026-08-01 13h17 +00:00 |
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server ... |
8.8 |
High |
|
CVE-2026-67342 |
2026-08-01 13h17 +00:00 |
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for t... Authorization problems |
9.8 |
Critical |
|
CVE-2026-67341 |
2026-08-01 13h17 +00:00 |
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUN... Authorization problems |
9.8 |
Critical |
|
CVE-2026-67340 |
2026-08-01 13h17 +00:00 |
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang... Code Injection |
9.8 |
Critical |