CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-48949
6.1 MEDIUM

Lack of validation leads to an XSS vulnerability in the MFA management views.

Jul 7, 2026
CVE-2026-48948
8.8 HIGH

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

Jul 7, 2026
CVE-2026-48947
4.9 MEDIUM

An improper access check allows privileged users to overwrite media files without editing permissions.

Jul 7, 2026
CVE-2026-57851
7.8 HIGH

MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory …

Jul 7, 2026
CVE-2026-23698
7.2 HIGH

Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-level attackers to upload arbitrary PHP …

Jul 7, 2026
CVE-2026-23697
8.8 HIGH

Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing …

Jul 7, 2026
CVE-2026-14904
6.5 MEDIUM

AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources …

Jul 7, 2026
CVE-2026-13020
8.1 HIGH

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, …

Jul 7, 2026
CVE-2026-13019
9.8 CRITICAL

Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated …

Jul 7, 2026
CVE-2025-12799
6.5 MEDIUM

A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters …

Jul 7, 2026
CVE-2026-56812
7.5 HIGH

Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript client) allows an attacker with ordinary channel access to cause a persistent …

Jul 7, 2026
CVE-2026-56811
7.5 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) allows an unauthenticated attacker to cause a denial of service against any …

Jul 7, 2026
CVE-2026-14969
4.4 MEDIUM

A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an …

Jul 7, 2026
CVE-2026-14935
3.7 LOW

A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers …

Jul 7, 2026
CVE-2026-59709
4.3 MEDIUM

Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field when processing the Impersonation-Id header, allowing read-only access grantees to modify portfolio holding tags. Attackers with …

Jul 7, 2026
CVE-2026-53878
6.1 MEDIUM

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a …

Jul 7, 2026
CVE-2026-53877
4.8 MEDIUM

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when constructed from a bytes object, which …

Jul 7, 2026
CVE-2026-48588
3.1 LOW

An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when …

Jul 7, 2026
CVE-2026-14940
5.3 MEDIUM

A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested …

Jul 7, 2026
CVE-2026-12948

A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP, Digi One SP IA, and Digi …

Jul 7, 2026
CVE-2026-12352
5.9 MEDIUM

This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device.

Jul 7, 2026
CVE-2026-6101
7.5 HIGH

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This …

Jul 7, 2026
CVE-2026-53479
7.2 HIGH

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through …

Jul 7, 2026
CVE-2026-44938
8.8 HIGH

A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (or BundleDeployment.spec.options.namespaceLabels) when applying them to …

Jul 7, 2026
CVE-2026-53483
9.8 CRITICAL

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through …

Jul 7, 2026
CVE-2026-53481
9.8 CRITICAL

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through …

Jul 7, 2026
CVE-2026-10659
4.7 MEDIUM

The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, on a flash error, the error code was written unconditionally through …

Jul 7, 2026
CVE-2026-13696
8.8 HIGH

Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman …

Jul 7, 2026
CVE-2026-11348
8.1 HIGH

Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107.

Jul 7, 2026
CVE-2011-10043
9.8 CRITICAL

Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the …

Jul 7, 2026
CVE-2026-11340
8.3 HIGH

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107.

Jul 7, 2026
CVE-2026-49487
6.5 MEDIUM

In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger kwargs without masking. When a deferred operator …

Jul 7, 2026
CVE-2026-49296
6.5 MEDIUM

Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` …

Jul 7, 2026
CVE-2026-48892
6.5 MEDIUM

The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not …

Jul 7, 2026
CVE-2026-48891
4.3 MEDIUM

A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag …

Jul 7, 2026
CVE-2026-48828
6.5 MEDIUM

The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key …

Jul 7, 2026
CVE-2026-33264
9.8 CRITICAL

A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could …

Jul 7, 2026
CVE-2026-14868
5.5 MEDIUM

The encryption algorithm used to protect the configuration of user accounts, stored in the built-in user directory of PcVue projects, all versions prior to 17.0.0, …

Jul 7, 2026
CVE-2026-14867
5.5 MEDIUM

Credentials of built-in users are insecurely stored in the User directory of PcVue projects, all versions prior to 17.0.0. A local attacker could retrieve users’ …

Jul 7, 2026
CVE-2026-14476
8.0 HIGH

A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing …

Jul 7, 2026
CVE-2026-14474
8.8 HIGH

A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for …

Jul 7, 2026
CVE-2026-11610
8.8 HIGH

A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection …

Jul 7, 2026
CVE-2026-58384
7.3 HIGH

A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after …

Jul 7, 2026
CVE-2026-13199
4.0 MEDIUM

EEPROM firmware on Raspberry Pi 5 and Compute Module 5 devices produced non-random KASLR and RNG seed values. This resulted in consistent kernel addresses across …

Jul 7, 2026
CVE-2026-8377
8.2 HIGH

Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control …

Jul 7, 2026
CVE-2026-8309
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This …

Jul 7, 2026
CVE-2026-8306
6.1 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This …

Jul 7, 2026
CVE-2026-7380
6.1 MEDIUM

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS …

Jul 7, 2026
CVE-2026-5799
7.5 HIGH

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.

Jul 7, 2026
CVE-2026-5730
7.5 HIGH

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted Identifiers. This issue affects Ontime: through 04052026.

Jul 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.