CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2018-25418
8.2 HIGH

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. …

May 30, 2026
CVE-2018-25417
8.2 HIGH

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. …

May 30, 2026
CVE-2018-25416
8.2 HIGH

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. …

May 30, 2026
CVE-2018-25415
8.2 HIGH

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. …

May 30, 2026
CVE-2018-25414
8.2 HIGH

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. …

May 30, 2026
CVE-2018-25413
8.2 HIGH

AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. …

May 30, 2026
CVE-2018-25411
8.2 HIGH

MGB OpenSource Guestbook 0.7.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' …

May 30, 2026
CVE-2018-25410
7.1 HIGH

SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers …

May 30, 2026
CVE-2018-25409
8.8 HIGH

SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers …

May 30, 2026
CVE-2018-25408
7.5 HIGH

The Open ISES Project 3.30A contains a path traversal vulnerability in the ajax/download.php endpoint that allows unauthenticated attackers to download arbitrary files by manipulating the …

May 30, 2026
CVE-2018-25407
8.2 HIGH

eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. …

May 30, 2026
CVE-2018-25406
8.2 HIGH

eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. …

May 30, 2026
CVE-2018-25405
8.2 HIGH

eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through parameters in mod.php. …

May 30, 2026
CVE-2026-10120
8.8 HIGH

A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name …

May 30, 2026
CVE-2026-10119
8.8 HIGH

A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name …

May 30, 2026
CVE-2026-46242
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ep_remove_file()) cleared file->f_ep under …

May 30, 2026
CVE-2026-9757
7.5 HIGH

The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, …

May 30, 2026
CVE-2026-7465
8.8 HIGH

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, …

May 30, 2026
CVE-2026-7459
7.5 HIGH

The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subscriber+) account takeover in all versions up to, …

May 30, 2026
CVE-2026-10111
7.3 HIGH

A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument …

May 30, 2026
CVE-2026-10110
7.3 HIGH

A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the …

May 30, 2026
CVE-2026-48557
8.8 HIGH

Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension …

May 29, 2026
CVE-2026-48555
7.4 HIGH

Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound …

May 29, 2026
CVE-2026-47123
7.5 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command …

May 29, 2026
CVE-2026-46599
7.5 HIGH

The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image …

May 29, 2026
CVE-2026-46527
7.5 HIGH

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an …

May 29, 2026
CVE-2026-44422
7.5 HIGH

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple …

May 29, 2026
CVE-2026-44421
8.8 HIGH

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP …

May 29, 2026
CVE-2026-44420
8.8 HIGH

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side …

May 29, 2026
CVE-2026-44285
7.7 HIGH

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress …

May 29, 2026
CVE-2026-49374
7.6 HIGH

In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters

May 29, 2026
CVE-2026-49373
7.1 HIGH

In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings

May 29, 2026
CVE-2026-49372
7.5 HIGH

In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible

May 29, 2026
CVE-2026-49371
7.1 HIGH

In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible

May 29, 2026
CVE-2026-49368
8.7 HIGH

In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible

May 29, 2026
CVE-2026-49367
8.0 HIGH

In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account

May 29, 2026
CVE-2026-49366
7.8 HIGH

In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion

May 29, 2026
CVE-2026-47740
8.1 HIGH

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by …

May 29, 2026
CVE-2026-46372
8.5 HIGH

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. …

May 29, 2026
CVE-2026-44648
7.5 HIGH

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. …

May 29, 2026
CVE-2026-42941
8.3 HIGH

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

May 29, 2026
CVE-2026-42929
8.3 HIGH

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

May 29, 2026
CVE-2026-6824
8.4 HIGH

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers …

May 29, 2026
CVE-2026-5768
8.8 HIGH

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range …

May 29, 2026
CVE-2026-47179
7.7 HIGH

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive …

May 29, 2026
CVE-2026-47125
8.8 HIGH

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file …

May 29, 2026
CVE-2026-45627
8.2 HIGH

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query …

May 29, 2026
CVE-2026-44697
8.6 HIGH

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that …

May 29, 2026
CVE-2026-10108
7.5 HIGH

xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated attackers to read arbitrary files outside the intended music …

May 29, 2026
CVE-2026-10107
7.7 HIGH

MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated attackers to request arbitrary URLs by supplying a resource_token …

May 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.