CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50179
4.2 MEDIUM

Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/src/server/transactions/export/export-to-csv.ts pass user-controlled Payee, Notes, Account, and Category strings to csv-stringify …

Jul 7, 2026
CVE-2026-49229
8.3 HIGH

Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, …

Jul 7, 2026
CVE-2026-49033
7.8 HIGH

The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code.

Jul 7, 2026
CVE-2026-46354
9.1 CRITICAL

Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the …

Jul 7, 2026
CVE-2026-45796
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind …

Jul 7, 2026
CVE-2026-42958
7.8 HIGH

The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This could allow an attacker to …

Jul 7, 2026
CVE-2026-42953

The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of …

Jul 7, 2026
CVE-2026-28378
3.1 LOW

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different …

Jul 7, 2026
CVE-2026-59707
8.6 HIGH

LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that allows attackers to fetch arbitrary internal URLs. The endpoint passes unsanitized …

Jul 7, 2026
CVE-2026-58583
7.1 HIGH

FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user account via arbitrary physical memory mapping at …

Jul 7, 2026
CVE-2026-58473
9.1 CRITICAL

Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and …

Jul 7, 2026
CVE-2026-58472
5.9 MEDIUM

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker …

Jul 7, 2026
CVE-2026-58471
5.9 MEDIUM

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to …

Jul 7, 2026
CVE-2026-58470
5.3 MEDIUM

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause …

Jul 7, 2026
CVE-2026-58469
7.5 HIGH

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server …

Jul 7, 2026
CVE-2026-57172

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded default share link signature key, allowing an attacker …

Jul 7, 2026
CVE-2026-55647

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stored component content with Vue v-html without server-side …

Jul 7, 2026
CVE-2026-55635

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed attacker-controlled filter values directly into generated …

Jul 7, 2026
CVE-2026-55633

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows …

Jul 7, 2026
CVE-2026-55631

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows authenticated users to submit an arbitrary fileTransName …

Jul 7, 2026
CVE-2026-55592
3.9 LOW

Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and assigns it directly to an iframe source …

Jul 7, 2026
CVE-2026-55434
6.5 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers …

Jul 7, 2026
CVE-2026-55417

Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile option, visiting their …

Jul 7, 2026
CVE-2026-53935
6.9 MEDIUM

Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 to 1.19.3, users with the ability to …

Jul 7, 2026
CVE-2026-53751

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation logic can be bypassed with special …

Jul 7, 2026
CVE-2026-53730

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql endpoint lacks the mandatory @DePermit permission validation annotation, allowing any …

Jul 7, 2026
CVE-2026-53729

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (/exportCenter/download/{id}), delete (/exportCenter/delete), retry (/exportCenter/retry/{id}), or generate …

Jul 7, 2026
CVE-2026-53511

calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when its metadata is read …

Jul 7, 2026
CVE-2026-50530

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface only validates that sceneId matches the …

Jul 7, 2026
CVE-2026-50529

DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share interface generates and returns X-DE-LINK-TOKEN before validating the share …

Jul 7, 2026
CVE-2026-50007

Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared user with user_access on a budget file to …

Jul 7, 2026
CVE-2026-49471
8.3 HIGH

Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, Serena's built-in web dashboard exposes an unauthenticated …

Jul 7, 2026
CVE-2026-46700
4.3 MEDIUM

Actual is a local-first personal finance tool. Prior to 26.6.0, the GET /secret/:name endpoint in @actual-app/sync-server checks only that the caller has a valid session …

Jul 7, 2026
CVE-2026-46672
4.6 MEDIUM

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in packages/cli/src/output.ts used whenever the global --format csv option …

Jul 7, 2026
CVE-2026-44454
8.1 HIGH

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to …

Jul 7, 2026
CVE-2026-58468
5.5 MEDIUM

NocoBase through 2.1.20 contains a server-side request forgery vulnerability in the serverRequest wrapper that allows authenticated administrators to issue arbitrary outbound HTTP requests by supplying …

Jul 7, 2026
CVE-2026-44877
6.5 MEDIUM

An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploitation of this vulnerability could allow …

Jul 7, 2026
CVE-2026-7017
7.1 HIGH

HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets. When the server returns a 3xx redirect, `_maybe_redirect` follows the `Location:` header …

Jul 7, 2026
CVE-2026-59800
9.8 CRITICAL

9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, …

Jul 7, 2026
CVE-2026-59708
7.5 HIGH

The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private …

Jul 7, 2026
CVE-2026-55435
5.4 MEDIUM

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy …

Jul 7, 2026
CVE-2026-48958
8.8 HIGH

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

Jul 7, 2026
CVE-2026-48957
8.8 HIGH

An improper access check allows unauthorized users to access com_privacy datasets.

Jul 7, 2026
CVE-2026-48956
5.0 MEDIUM

An improper access check allows users to display a list of modules in the frontend.

Jul 7, 2026
CVE-2026-48955
6.5 MEDIUM

An improper access check allows unauthorized users to access workflow stage and transition information.

Jul 7, 2026
CVE-2026-48954
6.1 MEDIUM

Improper validation leads to a generic XSS vector in the language override feature.

Jul 7, 2026
CVE-2026-48953
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

Jul 7, 2026
CVE-2026-48952
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

Jul 7, 2026
CVE-2026-48951
6.1 MEDIUM

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

Jul 7, 2026
CVE-2026-48950
6.1 MEDIUM

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

Jul 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.