CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-57231
7.5 HIGH

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

Sep 10, 2026
CVE-2026-9667
5.3 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server …

Sep 10, 2026
CVE-2026-9327
6.3 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in …

Sep 10, 2026
CVE-2026-9225
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control …

Sep 10, 2026
CVE-2026-9176
6.7 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability …

Sep 10, 2026
CVE-2026-89094
9.9 CRITICAL

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Sep 10, 2026
CVE-2026-89089
6.5 MEDIUM

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run …

Sep 10, 2026
CVE-2026-85025
9.8 CRITICAL

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared …

Sep 10, 2026
CVE-2026-79592
7.5 HIGH

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

Sep 10, 2026
CVE-2026-79591
7.8 HIGH

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

Sep 10, 2026
CVE-2026-76653

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper …

Sep 10, 2026
CVE-2026-76652

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient …

Sep 10, 2026
CVE-2026-75940
9.1 CRITICAL

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

Sep 10, 2026
CVE-2026-63427
7.8 HIGH

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

Sep 10, 2026
CVE-2026-45761
3.3 LOW

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using …

Sep 10, 2026
CVE-2026-45759
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform …

Sep 10, 2026
CVE-2026-45752
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when …

Sep 10, 2026
CVE-2026-45751
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's inspection-buffer helper could …

Sep 10, 2026
CVE-2026-3096
4.7 MEDIUM

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the …

Sep 10, 2026
CVE-2026-19596
5.9 MEDIUM

An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a …

Sep 10, 2026
CVE-2026-19136
7.8 HIGH

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system …

Sep 10, 2026
CVE-2026-18994
7.1 HIGH

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local …

Sep 10, 2026
CVE-2026-11813
7.8 HIGH

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

Sep 10, 2026
CVE-2022-26962
5.4 MEDIUM

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. …

Sep 10, 2026
CVE-2026-89087
7.3 HIGH

The cstruct package before 6.3.0 for OCaml mishandles indexes.

Sep 10, 2026
CVE-2026-89086
9.1 CRITICAL

In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to …

Sep 10, 2026
CVE-2026-89054
8.2 HIGH

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for …

Sep 10, 2026
CVE-2026-89011
7.1 HIGH

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted …

Sep 10, 2026
CVE-2026-88062

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent …

Sep 10, 2026
CVE-2026-88061

career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api …

Sep 10, 2026
CVE-2026-84432

Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a …

Sep 10, 2026
CVE-2026-9338
5.3 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit …

Sep 10, 2026
CVE-2026-9336
6.5 MEDIUM

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. …

Sep 10, 2026
CVE-2026-89049
9.9 CRITICAL

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems …

Sep 10, 2026
CVE-2026-88060

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side …

Sep 10, 2026
CVE-2026-88059
4.0 MEDIUM

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common …

Sep 10, 2026
CVE-2026-88058

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side …

Sep 10, 2026
CVE-2026-88057

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler …

Sep 10, 2026
CVE-2026-88056

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side …

Sep 10, 2026
CVE-2026-88036
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88035
4.7 MEDIUM

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and …

Sep 10, 2026
CVE-2026-88034
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88033
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88032
5.9 MEDIUM

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation …

Sep 10, 2026
CVE-2026-88021
7.1 HIGH

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it …

Sep 10, 2026
CVE-2026-87993
7.7 HIGH

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template …

Sep 10, 2026
CVE-2026-87107
5.4 MEDIUM

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported …

Sep 10, 2026
CVE-2026-87106
6.5 MEDIUM

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server …

Sep 10, 2026
CVE-2026-87090
8.3 HIGH

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's …

Sep 10, 2026
CVE-2026-68527

Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.