CVE Find is a real-time vulnerability database indexing 381 632 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 3538 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-19883 |
2026-08-22 03h16 +00:00 |
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of da... Improper Privilege Management |
8.8 |
High |
|
CVE-2026-53528 |
2026-08-21 22h16 +00:00 |
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in... |
8.8 |
High |
|
CVE-2026-53527 |
2026-08-21 22h16 +00:00 |
LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerabil... Improper Privilege Management |
8.8 |
High |
|
CVE-2026-49849 |
2026-08-21 22h16 +00:00 |
xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xSho... File Inclusion |
9.1 |
Critical |
|
CVE-2026-34741 |
2026-08-21 22h16 +00:00 |
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows... Authorization problems |
8.6 |
High |
|
CVE-2026-33240 |
2026-08-21 22h16 +00:00 |
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-... Cross-site Scripting |
8.8 |
High |
|
CVE-2026-31936 |
2026-08-21 22h16 +00:00 |
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthor... Authorization problems |
8.8 |
High |
|
CVE-2026-77811 |
2026-08-21 21h17 +00:00 |
Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a r... Cross-site Scripting |
8.7 |
High |
|
CVE-2026-76904 |
2026-08-21 21h17 +00:00 |
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version... SQL Injection |
9.8 |
Critical |
|
CVE-2026-63135 |
2026-08-21 21h17 +00:00 |
YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS ... Cross-site Scripting |
8.2 |
High |