CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10201
3.3 LOW

A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects of the file FBXExporter.cpp of the component UV Channel Handler. …

Jun 1, 2026
CVE-2026-10199
3.3 LOW

A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of …

May 31, 2026
CVE-2026-10198
3.3 LOW

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component …

May 31, 2026
CVE-2026-10197
3.3 LOW

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The …

May 31, 2026
CVE-2026-10169
3.7 LOW

A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php …

May 31, 2026
CVE-2026-10112
2.4 LOW

A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. Affected is an unknown function of the component Dashboard Page. The manipulation of the argument Name …

May 30, 2026
CVE-2026-45613
3.3 LOW

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bin/format/omf/omf.c. This vulnerability is fixed by commit e6d0937c8a083e23ed76ccfb9f631cdc50c7af47.

May 29, 2026
CVE-2026-45324
3.3 LOW

Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cmd_search.c:byte_pattern_search() due wrong pointer ownership declared. This vulnerability is …

May 29, 2026
CVE-2026-49383
3.3 LOW

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

May 29, 2026
CVE-2026-49381
3.4 LOW

In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible

May 29, 2026
CVE-2026-49380
3.1 LOW

In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible

May 29, 2026
CVE-2026-49370
3.4 LOW

In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests

May 29, 2026
CVE-2026-49318
2.4 LOW

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker …

May 29, 2026
CVE-2026-49317
2.4 LOW

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker …

May 29, 2026
CVE-2026-40528
3.8 LOW

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to …

May 29, 2026
CVE-2026-40510
3.8 LOW

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory …

May 29, 2026
CVE-2026-10078
2.7 LOW

A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, specifically client_id and client_secret, to be transmitted as plaintext …

May 29, 2026
CVE-2026-9991
3.1 LOW

Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin …

May 28, 2026
CVE-2026-9959
3.1 LOW

Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

May 28, 2026
CVE-2026-9950
3.1 LOW

Insufficient validation of untrusted input in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process …

May 28, 2026
CVE-2026-9944
3.1 LOW

Uninitialized Use in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

May 28, 2026
CVE-2026-9920
3.1 LOW

Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin …

May 28, 2026
CVE-2026-6816
3.8 LOW

An access bypass vulnerability in Drupal TFA Basic Plugins allows users with the administer users permission to view or generate recovery codes for other users. …

May 28, 2026
CVE-2026-10011
3.1 LOW

Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

May 28, 2026
CVE-2026-47713
2.0 LOW

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved …

May 28, 2026
CVE-2026-45403
2.0 LOW

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM …

May 28, 2026
CVE-2026-47337
3.3 LOW

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can …

May 28, 2026
CVE-2026-47336
3.3 LOW

Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered …

May 28, 2026
CVE-2026-47330
3.3 LOW

Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug …

May 28, 2026
CVE-2026-47329
3.3 LOW

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug …

May 28, 2026
CVE-2026-47327
3.3 LOW

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be …

May 28, 2026
CVE-2026-48524
3.7 LOW

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT …

May 28, 2026
CVE-2026-48156
3.3 LOW

pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to …

May 28, 2026
CVE-2026-49009
3.1 LOW

Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal.

May 27, 2026
CVE-2026-33552
3.7 LOW

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

May 27, 2026
CVE-2026-44474
3.7 LOW

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures …

May 27, 2026
CVE-2026-42082
3.7 LOW

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules …

May 27, 2026
CVE-2026-42791
3.7 LOW

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. …

May 27, 2026
CVE-2024-47272
2.7 LOW

Incorrect authorization vulnerability in IO Module functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to limited file …

May 27, 2026
CVE-2024-47270
2.7 LOW

Improper preservation of permissions vulnerability in Archiving Push functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows remote authenticated users with administrator privileges to …

May 27, 2026
CVE-2024-47267
2.7 LOW

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Archiving Pull functionality in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575 allows …

May 27, 2026
CVE-2026-9608
2.4 LOW

A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator …

May 27, 2026
CVE-2025-68711
2.4 LOW

AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is …

May 26, 2026
CVE-2025-68708
2.4 LOW

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an …

May 26, 2026
CVE-2025-68710
2.4 LOW

Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is …

May 26, 2026
CVE-2026-9572
3.3 LOW

A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the …

May 26, 2026
CVE-2026-9567
3.3 LOW

A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The …

May 26, 2026
CVE-2026-42448
3.5 LOW

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traversal when …

May 26, 2026
CVE-2026-9564
2.4 LOW

A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Performing a …

May 26, 2026
CVE-2026-47716
3.1 LOW

Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes access through the project in the URL, …

May 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.