CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81275
6.5 MEDIUM

Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.

Sep 10, 2026
CVE-2026-78536
6.5 MEDIUM

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

Sep 10, 2026
CVE-2026-66674
5.6 MEDIUM

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

Sep 10, 2026
CVE-2026-66632
6.5 MEDIUM

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

Sep 10, 2026
CVE-2026-46387
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path …

Sep 10, 2026
CVE-2026-45747
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper …

Sep 10, 2026
CVE-2026-15461
5.3 MEDIUM

The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) …

Sep 10, 2026
CVE-2026-88921

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML …

Sep 10, 2026
CVE-2026-88915

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can …

Sep 10, 2026
CVE-2026-88896
5.3 MEDIUM

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) …

Sep 10, 2026
CVE-2026-88895
7.2 HIGH

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's …

Sep 10, 2026
CVE-2026-88894
5.4 MEDIUM

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, …

Sep 10, 2026
CVE-2026-88893
7.5 HIGH

OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link …

Sep 10, 2026
CVE-2026-88892
5.0 MEDIUM

OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain …

Sep 10, 2026
CVE-2026-88891
8.3 HIGH

OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers …

Sep 10, 2026
CVE-2026-88890
8.5 HIGH

OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them …

Sep 10, 2026
CVE-2026-88889
7.8 HIGH

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType …

Sep 10, 2026
CVE-2026-88888
7.0 HIGH

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters …

Sep 10, 2026
CVE-2026-88887
8.6 HIGH

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the …

Sep 10, 2026
CVE-2026-88886
7.8 HIGH

Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before …

Sep 10, 2026
CVE-2026-88885
7.0 HIGH

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers …

Sep 10, 2026
CVE-2026-88884
5.8 MEDIUM

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm …

Sep 10, 2026
CVE-2026-88883
7.7 HIGH

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), …

Sep 10, 2026
CVE-2026-88882
8.6 HIGH

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before …

Sep 10, 2026
CVE-2026-88881
8.6 HIGH

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, …

Sep 10, 2026
CVE-2026-88880
8.6 HIGH

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised …

Sep 10, 2026
CVE-2026-88879
8.2 HIGH

Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on …

Sep 10, 2026
CVE-2026-88878
5.3 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings …

Sep 10, 2026
CVE-2026-88877
9.8 CRITICAL

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both …

Sep 10, 2026
CVE-2026-88876
7.5 HIGH

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password …

Sep 10, 2026
CVE-2026-88875
4.3 MEDIUM

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user …

Sep 10, 2026
CVE-2026-88874
7.5 HIGH

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) …

Sep 10, 2026
CVE-2026-88873
7.1 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests …

Sep 10, 2026
CVE-2026-88872
7.1 HIGH

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by …

Sep 10, 2026
CVE-2026-88871
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script reads users_id and ExtraSubscribers …

Sep 10, 2026
CVE-2026-88870
7.1 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can …

Sep 10, 2026
CVE-2026-88869
9.3 CRITICAL

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. …

Sep 10, 2026
CVE-2026-88868
8.7 HIGH

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user …

Sep 10, 2026
CVE-2026-88867
8.7 HIGH

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to …

Sep 10, 2026
CVE-2026-88866
8.7 HIGH

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it …

Sep 10, 2026
CVE-2026-88865
8.1 HIGH

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can …

Sep 10, 2026
CVE-2026-88864
9.1 CRITICAL

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key …

Sep 10, 2026
CVE-2026-88863
8.1 HIGH

capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The …

Sep 10, 2026
CVE-2026-88862
8.8 HIGH

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID …

Sep 10, 2026
CVE-2026-88861
8.3 HIGH

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase …

Sep 10, 2026
CVE-2026-88860
6.3 MEDIUM

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific …

Sep 10, 2026
CVE-2026-88790
4.8 MEDIUM

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File …

Sep 10, 2026
CVE-2026-85217
8.6 HIGH

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful …

Sep 10, 2026
CVE-2026-75584
7.5 HIGH

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with …

Sep 10, 2026
CVE-2026-6285
7.5 HIGH

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.