CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-18900
7.2 HIGH

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation …

Aug 5, 2026
CVE-2026-18898
8.8 HIGH

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of …

Aug 5, 2026
CVE-2026-18897
8.8 HIGH

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of …

Aug 5, 2026
CVE-2026-18895
8.8 HIGH

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the …

Aug 5, 2026
CVE-2026-18859
7.3 HIGH

A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid …

Aug 5, 2026
CVE-2026-18854
7.3 HIGH

A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the …

Aug 5, 2026
CVE-2026-70619
8.8 HIGH

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes …

Aug 4, 2026
CVE-2026-67862
7.5 HIGH

open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.

Aug 4, 2026
CVE-2026-67861
7.5 HIGH

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

Aug 4, 2026
CVE-2026-67860
7.5 HIGH

open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.

Aug 4, 2026
CVE-2026-67859
7.5 HIGH

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

Aug 4, 2026
CVE-2026-67858
7.5 HIGH

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated …

Aug 4, 2026
CVE-2026-67857
7.5 HIGH

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

Aug 4, 2026
CVE-2026-67856
7.5 HIGH

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions …

Aug 4, 2026
CVE-2026-67855
7.5 HIGH

open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial …

Aug 4, 2026
CVE-2026-45103
7.5 HIGH

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header …

Aug 4, 2026
CVE-2026-18814
7.2 HIGH

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack …

Aug 4, 2026
CVE-2026-70494
8.1 HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted …

Aug 4, 2026
CVE-2026-70492
8.7 HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math …

Aug 4, 2026
CVE-2026-66901
7.5 HIGH

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the …

Aug 4, 2026
CVE-2026-51401
7.7 HIGH

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

Aug 4, 2026
CVE-2026-51400
8.4 HIGH

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

Aug 4, 2026
CVE-2026-18813
7.2 HIGH

A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads …

Aug 4, 2026
CVE-2026-18812
7.2 HIGH

A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the …

Aug 4, 2026
CVE-2026-18811
7.2 HIGH

A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument …

Aug 4, 2026
CVE-2026-70486
8.2 HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together …

Aug 4, 2026
CVE-2026-70485
7.1 HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally …

Aug 4, 2026
CVE-2026-70482
8.1 HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and …

Aug 4, 2026
CVE-2026-70479
7.7 HIGH

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level …

Aug 4, 2026
CVE-2026-18810
7.3 HIGH

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. …

Aug 4, 2026
CVE-2026-18657
7.8 HIGH

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a …

Aug 4, 2026
CVE-2026-18656
7.8 HIGH

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a …

Aug 4, 2026
CVE-2026-16793
8.8 HIGH

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an …

Aug 4, 2026
CVE-2026-47623
8.2 HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to …

Aug 4, 2026
CVE-2026-47618
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of …

Aug 4, 2026
CVE-2026-47617
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful …

Aug 4, 2026
CVE-2026-47616
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this …

Aug 4, 2026
CVE-2026-47615
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A …

Aug 4, 2026
CVE-2026-47614
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information …

Aug 4, 2026
CVE-2026-47613
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted …

Aug 4, 2026
CVE-2026-47612
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted …

Aug 4, 2026
CVE-2026-24255
7.5 HIGH

NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share …

Aug 4, 2026
CVE-2026-24253
8.2 HIGH

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial …

Aug 4, 2026
CVE-2026-18830
8.1 HIGH

Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via …

Aug 4, 2026
CVE-2026-18788
7.3 HIGH

A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation …

Aug 4, 2026
CVE-2026-56848
7.5 HIGH

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, …

Aug 4, 2026
CVE-2026-18787
8.8 HIGH

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC …

Aug 4, 2026
CVE-2026-15307
8.8 HIGH

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as a raster by …

Aug 4, 2026
CVE-2026-69100
8.8 HIGH

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database …

Aug 4, 2026
CVE-2026-25292
7.6 HIGH

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

Aug 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.