CVE Database

52018+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-49209
6.5 MEDIUM

Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full …

Jul 17, 2026
CVE-2026-49208
5.3 MEDIUM

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format …

Jul 17, 2026
CVE-2026-44722
6.2 MEDIUM

pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in …

Jul 17, 2026
CVE-2026-21761
4.2 MEDIUM

HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-origin requests, potentially exposing application resources to …

Jul 17, 2026
CVE-2026-21760
4.6 MEDIUM

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper authorization checks may allow unauthorized users to access restricted …

Jul 17, 2026
CVE-2026-16108
4.3 MEDIUM

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are automatically assigned …

Jul 17, 2026
CVE-2026-16106
4.9 MEDIUM

A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when a delegated administrator …

Jul 17, 2026
CVE-2026-16104
4.3 MEDIUM

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity …

Jul 17, 2026
CVE-2026-16103
4.3 MEDIUM

A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, where brute-force protection checks were added to …

Jul 17, 2026
CVE-2026-16093
5.4 MEDIUM

Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw …

Jul 17, 2026
CVE-2026-11763
6.5 MEDIUM

Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted …

Jul 17, 2026
CVE-2026-9537
5.3 MEDIUM

Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC …

Jul 17, 2026
CVE-2026-63100
6.5 MEDIUM

Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show …

Jul 17, 2026
CVE-2026-63099
6.5 MEDIUM

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other …

Jul 17, 2026
CVE-2026-63098
5.3 MEDIUM

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the …

Jul 17, 2026
CVE-2026-63097
4.3 MEDIUM

Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state …

Jul 17, 2026
CVE-2026-63096
5.8 MEDIUM

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts …

Jul 17, 2026
CVE-2026-63095
6.5 MEDIUM

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging …

Jul 17, 2026
CVE-2026-58149
5.3 MEDIUM

The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.

Jul 17, 2026
CVE-2026-51083
6.5 MEDIUM

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords …

Jul 17, 2026
CVE-2026-51081
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web …

Jul 17, 2026
CVE-2026-16089
5.4 MEDIUM

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly …

Jul 17, 2026
CVE-2026-16017
6.3 MEDIUM

A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron …

Jul 17, 2026
CVE-2026-12705
6.4 MEDIUM

Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through …

Jul 17, 2026
CVE-2026-16072
4.9 MEDIUM

A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a …

Jul 17, 2026
CVE-2026-16015
6.3 MEDIUM

A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. …

Jul 17, 2026
CVE-2024-42214
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the …

Jul 17, 2026
CVE-2024-23578
4.2 MEDIUM

HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from …

Jul 17, 2026
CVE-2024-23577
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. …

Jul 17, 2026
CVE-2024-23575
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker …

Jul 17, 2026
CVE-2024-23574
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid …

Jul 17, 2026
CVE-2024-23572
4.2 MEDIUM

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You …

Jul 17, 2026
CVE-2024-23571
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and …

Jul 17, 2026
CVE-2024-23570
4.3 MEDIUM

HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on …

Jul 17, 2026
CVE-2024-23569
4.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

Jul 17, 2026
CVE-2024-23568
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information …

Jul 17, 2026
CVE-2024-23567
4.3 MEDIUM

HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during …

Jul 17, 2026
CVE-2024-23566
6.5 MEDIUM

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force …

Jul 17, 2026
CVE-2024-23565
5.3 MEDIUM

HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor …

Jul 17, 2026
CVE-2026-13082
5.3 MEDIUM

GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters …

Jul 17, 2026
CVE-2026-16013
5.3 MEDIUM

A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation …

Jul 17, 2026
CVE-2026-16009
6.3 MEDIUM

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid …

Jul 17, 2026
CVE-2026-15943
5.5 MEDIUM

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an …

Jul 17, 2026
CVE-2026-9602
6.5 MEDIUM

Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious …

Jul 17, 2026
CVE-2026-8075
6.5 MEDIUM

Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user …

Jul 17, 2026
CVE-2026-16008
6.3 MEDIUM

A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled …

Jul 17, 2026
CVE-2026-9656
4.3 MEDIUM

The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Jul 17, 2026
CVE-2026-13402
5.3 MEDIUM

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one …

Jul 17, 2026
CVE-2026-12393
5.4 MEDIUM

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing …

Jul 17, 2026
CVE-2026-11966
5.3 MEDIUM

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions …

Jul 17, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.