CVE Database

57718+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-43753
4.6 MEDIUM

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, …

Jul 27, 2026
CVE-2026-43744
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma …

Jul 27, 2026
CVE-2026-43739
5.5 MEDIUM

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, …

Jul 27, 2026
CVE-2026-43738
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog …

Jul 27, 2026
CVE-2026-43714
5.5 MEDIUM

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS …

Jul 27, 2026
CVE-2026-43665
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able …

Jul 27, 2026
CVE-2026-28932
5.5 MEDIUM

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma …

Jul 27, 2026
CVE-2026-28900
5.5 MEDIUM

A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive …

Jul 27, 2026
CVE-2026-28849
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass …

Jul 27, 2026
CVE-2026-20672
5.5 MEDIUM

An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be …

Jul 27, 2026
CVE-2026-66018
6.5 MEDIUM

Build readers can access another repository's environment properties. A caller with read access to an ordinary repository can select a readable repository parameter while retrieving …

Jul 27, 2026
CVE-2026-65925
6.5 MEDIUM

A user with JFrog Artifactory Cargo remote repository read access could make Artifactory request unintended URLs and return the response.

Jul 27, 2026
CVE-2026-65924
6.5 MEDIUM

JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Server-Side Request Forgery (SSRF). An authenticated user - or, if anonymous access …

Jul 27, 2026
CVE-2026-65923
6.8 MEDIUM

A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user, under specific repository access conditions, to cause unintended server-side requests. The …

Jul 27, 2026
CVE-2026-65618
6.5 MEDIUM

Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and …

Jul 27, 2026
CVE-2026-64649
6.5 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 14.1.1 through 15.5.20 and 16.0.0 through 16.2.10, when a Server Action forwards or …

Jul 27, 2026
CVE-2026-64648
5.4 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request …

Jul 27, 2026
CVE-2026-66757
5.5 MEDIUM

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The …

Jul 27, 2026
CVE-2026-66031
5.4 MEDIUM

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by …

Jul 27, 2026
CVE-2026-64647
5.4 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a server-side fetch with a request …

Jul 27, 2026
CVE-2026-64646
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0 through 16.2.10, requests targeting Next.js applications using App …

Jul 27, 2026
CVE-2026-10682
6.6 MEDIUM

The userspace verifier z_vrfy_log_filter_set() for the log_filter_set syscall in subsys/logging/log_mgmt.c performed a signed comparison against the int16_t src_id parameter: src_id < (int16_t)log_src_cnt_get(domain_id). Any negative value …

Jul 27, 2026
CVE-2026-66030
5.4 MEDIUM

Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by …

Jul 27, 2026
CVE-2026-66029
5.4 MEDIUM

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by …

Jul 27, 2026
CVE-2026-66028
6.7 MEDIUM

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email …

Jul 27, 2026
CVE-2026-64645
6.1 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, a rewrites() or redirects() rule that …

Jul 27, 2026
CVE-2026-64644
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 15.5.0 through 15.5.20 and 16.0.0 through 16.2.10, when self-hosting Next.js with the default …

Jul 27, 2026
CVE-2026-64643
5.3 MEDIUM

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 through 16.2.10, Next.js applications using App Router, Server …

Jul 27, 2026
CVE-2026-48052
5.4 MEDIUM

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who is a member of any organization can delete …

Jul 27, 2026
CVE-2026-17570
4.3 MEDIUM

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API …

Jul 27, 2026
CVE-2026-17569
4.3 MEDIUM

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API …

Jul 27, 2026
CVE-2026-66391
6.5 MEDIUM

Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. …

Jul 27, 2026
CVE-2026-66390
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 …

Jul 27, 2026
CVE-2026-17531
5.0 MEDIUM

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the …

Jul 27, 2026
CVE-2026-66399
6.5 MEDIUM

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-management permissions to join privileged groups without verification of required …

Jul 27, 2026
CVE-2026-17530
6.3 MEDIUM

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.5. Affected by this vulnerability is the function _build_handoff_toolset of the file AstrBot/astrbot/core/astr_agent_tool_exec.py of …

Jul 27, 2026
CVE-2026-17529
6.3 MEDIUM

A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Affected is an unknown function of the file astrbot/core/astr_main_agent.py. The manipulation of the argument req.func_tool …

Jul 27, 2026
CVE-2026-66477
5.3 MEDIUM

Unauthenticated Broken Access Control in Gillion <= 4.13 versions.

Jul 27, 2026
CVE-2026-66476
4.9 MEDIUM

Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.

Jul 27, 2026
CVE-2026-66475
5.9 MEDIUM

Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce &#8211; Checkout Manager <= 3.0.5 versions.

Jul 27, 2026
CVE-2026-66474
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

Jul 27, 2026
CVE-2026-66448
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.

Jul 27, 2026
CVE-2026-66445
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.

Jul 27, 2026
CVE-2026-66442
5.4 MEDIUM

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

Jul 27, 2026
CVE-2026-66438
5.3 MEDIUM

Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor <= 2.8.0 versions.

Jul 27, 2026
CVE-2026-66437
4.9 MEDIUM

Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 versions.

Jul 27, 2026
CVE-2026-66434
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33 versions.

Jul 27, 2026
CVE-2026-66433
6.5 MEDIUM

Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.

Jul 27, 2026
CVE-2026-66428
4.3 MEDIUM

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

Jul 27, 2026
CVE-2026-65568
5.0 MEDIUM

Contributor Broken Access Control in Visual Composer Website Builder <= 45.15.0 versions.

Jul 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.