CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-43925

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self-registration endpoint allows …

Jul 6, 2026
CVE-2026-43921

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOSSBilling's `Config::prettyPrintArrayToPHP()` method. When …

Jul 6, 2026
CVE-2026-43918

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, …

Jul 6, 2026
CVE-2026-42204
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom …

Jul 6, 2026
CVE-2026-42153
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user …

Jul 6, 2026
CVE-2026-42148
3.8 LOW

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build …

Jul 6, 2026
CVE-2026-41899
6.5 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and …

Jul 6, 2026
CVE-2026-38979
5.4 MEDIUM

ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header …

Jul 6, 2026
CVE-2026-38976
7.5 HIGH

mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level …

Jul 6, 2026
CVE-2026-38973
4.4 MEDIUM

mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().

Jul 6, 2026
CVE-2026-34599
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, there is an authenticated command injection vulnerability in the …

Jul 6, 2026
CVE-2026-34167
5.0 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the ActivityMonitor Livewire component exposes a public $activityId property …

Jul 6, 2026
CVE-2026-34153
8.8 HIGH

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, LocalFileVolume::saveStorageOnServer builds shell commands using unescaped fs_path and parent_dir …

Jul 6, 2026
CVE-2026-34050
6.5 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in …

Jul 6, 2026
CVE-2026-34049
3.3 LOW

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did …

Jul 6, 2026
CVE-2026-32718
6.5 MEDIUM

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, …

Jul 6, 2026
CVE-2026-59713
8.1 HIGH

Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without validating state parameters. Attackers can craft malicious callback URLs …

Jul 6, 2026
CVE-2026-59712
8.1 HIGH

Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to retrieve full user credential rows including password hashes, TOTP secrets, …

Jul 6, 2026
CVE-2026-59711
6.1 MEDIUM

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped …

Jul 6, 2026
CVE-2026-57573
8.6 HIGH

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl …

Jul 6, 2026
CVE-2026-57572
10.0 CRITICAL

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. …

Jul 6, 2026
CVE-2026-57571
9.6 CRITICAL

Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from …

Jul 6, 2026
CVE-2026-55727
7.5 HIGH

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to …

Jul 6, 2026
CVE-2026-55574
7.5 HIGH

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular expression string …

Jul 6, 2026
CVE-2026-55514
6.5 MEDIUM

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with …

Jul 6, 2026
CVE-2026-54765
8.5 HIGH

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted …

Jul 6, 2026
CVE-2026-54764
5.8 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives …

Jul 6, 2026
CVE-2026-54763
10.0 CRITICAL

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity …

Jul 6, 2026
CVE-2026-54234
7.5 HIGH

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal multi-request speculative decoding workload can cause the rejection …

Jul 6, 2026
CVE-2026-50135
5.5 MEDIUM

Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows symlinks) instead of Lstat , so a direct …

Jul 6, 2026
CVE-2026-48267
5.5 MEDIUM

DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Jul 6, 2026
CVE-2026-42341

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerability in FOSSBilling's IPN callback endpoint. …

Jul 6, 2026
CVE-2026-42331

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an authorization check present …

Jul 6, 2026
CVE-2026-34038
9.9 CRITICAL

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment …

Jul 6, 2026
CVE-2026-33734

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Massmailer` module filter functionality. …

Jul 6, 2026
CVE-2026-25271
7.8 HIGH

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.

Jul 6, 2026
CVE-2026-25268
8.8 HIGH

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

Jul 6, 2026
CVE-2026-21384
5.3 MEDIUM

Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits.

Jul 6, 2026
CVE-2026-21383
7.1 HIGH

Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.

Jul 6, 2026
CVE-2026-21379
7.8 HIGH

Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.

Jul 6, 2026
CVE-2026-21370
5.3 MEDIUM

Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.

Jul 6, 2026
CVE-2026-21369
5.3 MEDIUM

Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.

Jul 6, 2026
CVE-2026-21368
5.3 MEDIUM

Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.

Jul 6, 2026
CVE-2026-14471
8.1 HIGH

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13 might allow an authenticated remote user to execute …

Jul 6, 2026
CVE-2026-14468
7.7 HIGH

HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce the intended boundary on …

Jul 6, 2026
CVE-2025-59617
6.6 MEDIUM

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.

Jul 6, 2026
CVE-2025-59616
6.6 MEDIUM

Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing already freed memory.

Jul 6, 2026
CVE-2025-59615
6.6 MEDIUM

Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffers due to improper synchronization.

Jul 6, 2026
CVE-2026-59089
5.5 MEDIUM

A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table …

Jul 6, 2026
CVE-2026-58404
6.8 MEDIUM

Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the …

Jul 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.