CVE Database

45572+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-25288
7.4 HIGH

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

Aug 4, 2026
CVE-2026-24084
7.5 HIGH

Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.

Aug 4, 2026
CVE-2026-24083
7.8 HIGH

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

Aug 4, 2026
CVE-2026-24080
7.8 HIGH

Memory Corruption when handling malformed request parameters in the fingerprint TA.

Aug 4, 2026
CVE-2026-24079
8.1 HIGH

Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.

Aug 4, 2026
CVE-2026-21366
7.8 HIGH

Memory corruption while processing a packet with a size close to the maximum allowed value.

Aug 4, 2026
CVE-2026-67200
7.5 HIGH

Perspective 5.0.0 contains a path traversal vulnerability that allows unauthenticated remote attackers to read arbitrary files from the server filesystem by including literal ../ segments …

Aug 4, 2026
CVE-2026-67198
7.5 HIGH

Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or …

Aug 4, 2026
CVE-2026-67195
8.8 HIGH

Perspective 5.0.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary operating system commands by submitting crafted expression strings to the …

Aug 4, 2026
CVE-2026-18770
7.3 HIGH

A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unknown function of the file /code of the component Python Validation …

Aug 4, 2026
CVE-2026-18650
8.8 HIGH

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Aug 4, 2026
CVE-2026-11368
7.1 HIGH

The Bluetooth host ATT layer (subsys/bluetooth/host/att.c) associates each in-flight ATT TX buffer with its owning channel via the static tx_meta_data_storage[] array (data->att_chan = chan). When …

Aug 4, 2026
CVE-2026-17070
8.8 HIGH

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

Aug 4, 2026
CVE-2026-70373
8.8 HIGH

Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The …

Aug 4, 2026
CVE-2026-70372
8.8 HIGH

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Criteria parameter is only normalized …

Aug 4, 2026
CVE-2026-70371
8.8 HIGH

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are …

Aug 4, 2026
CVE-2026-70370
8.8 HIGH

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT …

Aug 4, 2026
CVE-2026-70369
8.8 HIGH

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parameters directly into WHERE fragments covering aqbasket.closedate, aqorders.datereceived, aqbooksellers.name, …

Aug 4, 2026
CVE-2026-63252
7.5 HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote …

Aug 4, 2026
CVE-2026-62927
7.5 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or …

Aug 4, 2026
CVE-2026-61387
7.5 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is …

Aug 4, 2026
CVE-2026-60007
7.4 HIGH

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path …

Aug 4, 2026
CVE-2026-58080
8.2 HIGH

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running …

Aug 4, 2026
CVE-2026-18806
7.1 HIGH

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: …

Aug 4, 2026
CVE-2026-10710
7.8 HIGH

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage …

Aug 4, 2026
CVE-2026-10709
7.8 HIGH

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage …

Aug 4, 2026
CVE-2026-14838
7.4 HIGH

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Session Hijacking. This …

Aug 4, 2026
CVE-2026-67243
7.2 HIGH

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative privileges for the product may …

Aug 4, 2026
CVE-2026-18755
7.3 HIGH

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing …

Aug 4, 2026
CVE-2026-16623
8.0 HIGH

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite …

Aug 4, 2026
CVE-2026-42169
7.3 HIGH

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading …

Aug 4, 2026
CVE-2026-14818
7.2 HIGH

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, …

Aug 4, 2026
CVE-2026-6837
7.2 HIGH

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges …

Aug 4, 2026
CVE-2026-56846
7.5 HIGH

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and …

Aug 4, 2026
CVE-2026-56845
7.5 HIGH

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By including ../ sequences in the request path, an …

Aug 4, 2026
CVE-2026-66322
7.1 HIGH

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Aug 4, 2026
CVE-2026-66321
7.4 HIGH

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66318
8.1 HIGH

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-66315
7.5 HIGH

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-66310
7.7 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Aug 4, 2026
CVE-2026-65802
7.4 HIGH

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.

Aug 4, 2026
CVE-2026-62870
8.8 HIGH

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Aug 4, 2026
CVE-2026-67978
7.5 HIGH

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN …

Aug 3, 2026
CVE-2026-48399
7.5 HIGH

Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could …

Aug 3, 2026
CVE-2026-67977
7.5 HIGH

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 3, 2026
CVE-2026-67973
7.5 HIGH

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

Aug 3, 2026
CVE-2026-10849
8.2 HIGH

The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). …

Aug 3, 2026
CVE-2026-69246
7.2 HIGH

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host …

Aug 3, 2026
CVE-2026-67976
7.5 HIGH

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via …

Aug 3, 2026
CVE-2026-52521
8.1 HIGH

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.

Aug 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.