CVE Database

9856+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-47429
9.8 CRITICAL

Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing …

Jul 14, 2026
CVE-2026-47428
9.6 CRITICAL

Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted …

Jul 14, 2026
CVE-2026-15409
10.0 CRITICAL KEV

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance …

Jul 14, 2026
CVE-2026-13001
9.8 CRITICAL

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all …

Jul 14, 2026
CVE-2026-47767
9.8 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, …

Jul 14, 2026
CVE-2026-45069
9.1 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered …

Jul 14, 2026
CVE-2026-45063
9.1 CRITICAL

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator …

Jul 14, 2026
CVE-2026-57092
9.9 CRITICAL

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.

Jul 14, 2026
CVE-2026-56190
9.8 CRITICAL

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56188
9.8 CRITICAL

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-56159
9.8 CRITICAL

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-55944
9.8 CRITICAL

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-55040
9.1 CRITICAL

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Jul 14, 2026
CVE-2026-55010
9.8 CRITICAL

Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-50518
9.8 CRITICAL

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-50447
9.8 CRITICAL

Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-50380
9.6 CRITICAL

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-15747
9.1 CRITICAL

Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and …

Jul 14, 2026
CVE-2026-59891
9.6 CRITICAL

sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by …

Jul 14, 2026
CVE-2026-58644
9.8 CRITICAL KEV

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-55008
9.6 CRITICAL

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Jul 14, 2026
CVE-2026-54990
9.8 CRITICAL

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-50522
9.8 CRITICAL

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-49798
9.3 CRITICAL

Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-49172
9.8 CRITICAL

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-48561
9.6 CRITICAL

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-42990
9.8 CRITICAL

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

Jul 14, 2026
CVE-2026-15701
9.8 CRITICAL

A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. …

Jul 14, 2026
CVE-2026-60082
9.1 CRITICAL

DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source …

Jul 14, 2026
CVE-2026-58479
9.8 CRITICAL

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers …

Jul 14, 2026
CVE-2026-15265
9.1 CRITICAL

A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, …

Jul 14, 2026
CVE-2026-62392
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters …

Jul 14, 2026
CVE-2026-62390
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Kylin. A backend API refreshing table catalog may cause the …

Jul 14, 2026
CVE-2026-62422
10.0 CRITICAL

In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible

Jul 14, 2026
CVE-2026-58319
9.1 CRITICAL

Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could …

Jul 14, 2026
CVE-2026-56451
10.0 CRITICAL

A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web …

Jul 14, 2026
CVE-2026-3014
9.1 CRITICAL

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users …

Jul 14, 2026
CVE-2026-15043
9.8 CRITICAL

DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates …

Jul 14, 2026
CVE-2026-59084
9.1 CRITICAL

Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from …

Jul 14, 2026
CVE-2026-59083
9.1 CRITICAL

Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: …

Jul 14, 2026
CVE-2026-57898
9.0 CRITICAL

In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the …

Jul 14, 2026
CVE-2026-11563
9.6 CRITICAL

The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper authorization …

Jul 14, 2026
CVE-2026-44761
9.1 CRITICAL

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If …

Jul 14, 2026
CVE-2026-44747
9.9 CRITICAL

SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to …

Jul 14, 2026
CVE-2026-27690
9.1 CRITICAL

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. …

Jul 14, 2026
CVE-2026-58102
9.1 CRITICAL

Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building the extension hash (via …

Jul 13, 2026
CVE-2026-62327
9.1 CRITICAL

9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext API keys for all connected AI provider accounts …

Jul 13, 2026
CVE-2026-59801
9.8 CRITICAL

9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any …

Jul 13, 2026
CVE-2026-52533
9.8 CRITICAL

An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file

Jul 13, 2026
CVE-2026-51821
9.8 CRITICAL

SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint

Jul 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.