CVE Find est une base de données de vulnérabilités en temps réel, indexant 372 513 failles de sécurité (CVE) issues de MITRE, NVD, CISA KEV, CWE et CAPEC. 2095 nouvelles CVE ont été publiées ces 7 derniers jours.
Données agrégées depuis : MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Publié | Description | Score | Gravité | |
|---|---|---|---|---|---|
CVE-2026-65321 |
2026-08-02 14h56 +00:00 |
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attacker... SQL Injection |
9.3 |
Critique |
|
CVE-2026-68579 |
2026-08-02 13h16 +00:00 |
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard cli... Overflow |
9.6 |
Critique |
|
CVE-2026-67356 |
2026-08-02 13h16 +00:00 |
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with Hos... Improper Privilege Management |
8.8 |
Haute |
|
CVE-2025-71399 |
2026-08-02 13h16 +00:00 |
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3,... |
8.6 |
Haute |
|
CVE-2026-8457 |
2026-08-02 00h16 +00:00 |
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all ve... |
9.8 |
Critique |
|
CVE-2026-55735 |
2026-08-01 18h46 +00:00 |
Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated att... |
8.2 |
Haute |
|
CVE-2026-67343 |
2026-08-01 13h17 +00:00 |
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server ... |
8.8 |
Haute |
|
CVE-2026-67342 |
2026-08-01 13h17 +00:00 |
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for t... Authorization problems |
9.8 |
Critique |
|
CVE-2026-67341 |
2026-08-01 13h17 +00:00 |
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUN... Authorization problems |
9.8 |
Critique |
|
CVE-2026-67340 |
2026-08-01 13h17 +00:00 |
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang... Code Injection |
9.8 |
Critique |