CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89046
8.2 HIGH

zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values …

Sep 10, 2026
CVE-2026-89045
4.0 MEDIUM

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values …

Sep 10, 2026
CVE-2026-89044
6.5 MEDIUM

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle …

Sep 10, 2026
CVE-2026-89043
7.4 HIGH

passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any …

Sep 10, 2026
CVE-2026-89042
9.1 CRITICAL

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can …

Sep 10, 2026
CVE-2026-88055
5.5 MEDIUM

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the …

Sep 10, 2026
CVE-2026-88054
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack …

Sep 10, 2026
CVE-2026-88053
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of …

Sep 10, 2026
CVE-2026-88052
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and …

Sep 10, 2026
CVE-2026-88051
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved …

Sep 10, 2026
CVE-2026-88031
8.1 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88030
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88029
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88028
6.5 MEDIUM

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation …

Sep 10, 2026
CVE-2026-88027
7.1 HIGH

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded …

Sep 10, 2026
CVE-2026-88026
6.5 MEDIUM

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a …

Sep 10, 2026
CVE-2026-88025
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88024
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88023
8.3 HIGH

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier …

Sep 10, 2026
CVE-2026-88022
7.7 HIGH

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter …

Sep 10, 2026
CVE-2026-68006
9.1 CRITICAL

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

Sep 10, 2026
CVE-2026-15419

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel …

Sep 10, 2026
CVE-2026-15418

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up …

Sep 10, 2026
CVE-2026-15417

In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.

Sep 10, 2026
CVE-2026-88050
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted …

Sep 10, 2026
CVE-2026-88049
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but …

Sep 10, 2026
CVE-2026-88048
7.1 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ …

Sep 10, 2026
CVE-2026-88047
7.8 HIGH

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses …

Sep 10, 2026
CVE-2026-88046
5.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject …

Sep 10, 2026
CVE-2026-88045
7.5 HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed …

Sep 10, 2026
CVE-2026-88044
9.1 CRITICAL

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface …

Sep 10, 2026
CVE-2026-85228
9.1 CRITICAL

An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a …

Sep 10, 2026
CVE-2026-73699
7.2 HIGH

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in …

Sep 10, 2026
CVE-2026-73698
7.2 HIGH

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an …

Sep 10, 2026
CVE-2026-73694
7.2 HIGH

FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input …

Sep 10, 2026
CVE-2026-73693
8.8 HIGH

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by …

Sep 10, 2026
CVE-2026-68488
9.9 CRITICAL

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

Sep 10, 2026
CVE-2026-68487
9.9 CRITICAL

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Sep 10, 2026
CVE-2026-65639

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary …

Sep 10, 2026
CVE-2026-65638

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account …

Sep 10, 2026
CVE-2026-52098
9.8 CRITICAL

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

Sep 10, 2026
CVE-2026-52097
6.8 MEDIUM

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

Sep 10, 2026
CVE-2026-88959
8.8 HIGH

Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify …

Sep 10, 2026
CVE-2026-88940
5.3 MEDIUM

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host …

Sep 10, 2026
CVE-2026-88939
8.3 HIGH

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint …

Sep 10, 2026
CVE-2026-88938
6.5 MEDIUM

knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source …

Sep 10, 2026
CVE-2026-88937
8.8 HIGH

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside …

Sep 10, 2026
CVE-2026-88899
9.8 CRITICAL

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to …

Sep 10, 2026
CVE-2026-88018
9.8 CRITICAL

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with …

Sep 10, 2026
CVE-2026-88017
7.3 HIGH

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.