CVE Find is a real-time vulnerability database indexing 395 538 security flaws (CVE) from MITRE, NVD, CISA KEV, CWE and CAPEC. 4882 new CVEs were published in the last 7 days.
Data aggregated from: MITRE Corporation (CVE, CWE, CAPEC), National Vulnerability Database – NIST (NVD), CISA Known Exploited Vulnerabilities (KEV), FIRST (EPSS).
| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-86553 |
2026-09-20 03h17 +00:00 |
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its... Improper Privilege Management |
8.8 |
High |
|
CVE-2026-94083 |
2026-09-20 02h16 +00:00 |
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code... |
9.4 |
Critical |
|
CVE-2026-93958 |
2026-09-20 02h16 +00:00 |
A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function syst... Command InjectionOS Command Injection |
9.1 |
Critical |
|
CVE-2026-94084 |
2026-09-20 01h20 +00:00 |
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by r... Memory Corruption |
9.4 |
Critical |
|
CVE-2026-93993 |
2026-09-19 23h17 +00:00 |
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation p... |
8.8 |
High |
|
CVE-2026-93985 |
2026-09-19 12h16 +00:00 |
OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScri... Code Injection |
9.9 |
Critical |
|
CVE-2026-93742 |
2026-09-19 08h30 +00:00 |
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the ... Command Injection |
9.4 |
Critical |
|
CVE-2026-4327 |
2026-09-19 08h16 +00:00 |
The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to... Code Injection |
8.8 |
High |
|
CVE-2026-88926 |
2026-09-19 07h16 +00:00 |
The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise a... SQL Injection |
8.6 |
High |
|
CVE-2026-88824 |
2026-09-19 07h16 +00:00 |
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST rout... Cross-site Scripting |
8.8 |
High |