CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61589
6.3 MEDIUM

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via …

Sep 16, 2026
CVE-2026-61588
6.5 MEDIUM

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a …

Sep 16, 2026
CVE-2026-92598
6.5 MEDIUM

Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant …

Sep 16, 2026
CVE-2026-92597
6.5 MEDIUM

Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes …

Sep 16, 2026
CVE-2026-92595
5.9 MEDIUM

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public …

Sep 16, 2026
CVE-2026-92591
5.9 MEDIUM

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site …

Sep 16, 2026
CVE-2026-92590
5.4 MEDIUM

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to …

Sep 16, 2026
CVE-2026-92589
4.3 MEDIUM

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user …

Sep 16, 2026
CVE-2026-92588
4.4 MEDIUM

n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to …

Sep 16, 2026
CVE-2026-92587
5.0 MEDIUM

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath …

Sep 16, 2026
CVE-2026-92586
4.3 MEDIUM

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted …

Sep 16, 2026
CVE-2026-92585
4.3 MEDIUM

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted …

Sep 16, 2026
CVE-2026-92584
6.1 MEDIUM

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via …

Sep 16, 2026
CVE-2026-92583
6.5 MEDIUM

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate …

Sep 16, 2026
CVE-2026-92581
4.3 MEDIUM

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers …

Sep 16, 2026
CVE-2026-92579
5.4 MEDIUM

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to …

Sep 16, 2026
CVE-2026-89034
6.5 MEDIUM

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to …

Sep 16, 2026
CVE-2026-64684
6.8 MEDIUM

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest's …

Sep 16, 2026
CVE-2026-92814
4.2 MEDIUM

changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page …

Sep 16, 2026
CVE-2026-92813
4.9 MEDIUM

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save …

Sep 16, 2026
CVE-2026-92812
6.8 MEDIUM

decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix comparison without path separator validation. Attackers can access …

Sep 16, 2026
CVE-2026-92811
6.5 MEDIUM

browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints, allowing authenticated token holders to read arbitrary files. Attackers can …

Sep 16, 2026
CVE-2026-92810
4.3 MEDIUM

PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. …

Sep 16, 2026
CVE-2026-92809
4.3 MEDIUM

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer …

Sep 16, 2026
CVE-2026-92803
5.3 MEDIUM

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse …

Sep 16, 2026
CVE-2026-92802
4.3 MEDIUM

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. …

Sep 16, 2026
CVE-2026-92800
6.8 MEDIUM

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read …

Sep 16, 2026
CVE-2026-92795
6.5 MEDIUM

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. …

Sep 16, 2026
CVE-2026-92790
6.5 MEDIUM

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action …

Sep 16, 2026
CVE-2026-92789
6.5 MEDIUM

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or …

Sep 16, 2026
CVE-2026-92781
6.3 MEDIUM

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. …

Sep 16, 2026
CVE-2026-92778
5.4 MEDIUM

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can …

Sep 16, 2026
CVE-2026-92775
6.5 MEDIUM

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers …

Sep 16, 2026
CVE-2026-92774
4.3 MEDIUM

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, …

Sep 16, 2026
CVE-2026-92771
6.5 MEDIUM

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords …

Sep 16, 2026
CVE-2026-92770
6.5 MEDIUM

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the …

Sep 16, 2026
CVE-2026-92765
6.5 MEDIUM

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply …

Sep 16, 2026
CVE-2026-92764
4.3 MEDIUM

OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens …

Sep 16, 2026
CVE-2026-92760
6.5 MEDIUM

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with …

Sep 16, 2026
CVE-2026-92759
6.5 MEDIUM

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product …

Sep 16, 2026
CVE-2026-92754
4.3 MEDIUM

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with …

Sep 16, 2026
CVE-2026-92750
6.5 MEDIUM

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not …

Sep 16, 2026
CVE-2026-92527
6.3 MEDIUM

A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The …

Sep 16, 2026
CVE-2026-76451
4.9 MEDIUM

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL …

Sep 16, 2026
CVE-2026-76450
4.9 MEDIUM

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL …

Sep 16, 2026
CVE-2026-76449
4.9 MEDIUM

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL …

Sep 16, 2026
CVE-2026-76448
4.9 MEDIUM

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL …

Sep 16, 2026
CVE-2026-76447
5.3 MEDIUM

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an …

Sep 16, 2026
CVE-2026-76446
4.9 MEDIUM

A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific&nbsp;files on the underlying operating system …

Sep 16, 2026
CVE-2026-76444
5.3 MEDIUM

A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.