CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-79588
4.3 MEDIUM

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

Sep 8, 2026
CVE-2026-78971
4.6 MEDIUM

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

Sep 8, 2026
CVE-2026-78742
6.1 MEDIUM

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

Sep 8, 2026
CVE-2026-78741
6.1 MEDIUM

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

Sep 8, 2026
CVE-2026-78738
6.1 MEDIUM

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

Sep 8, 2026
CVE-2026-78635
5.0 MEDIUM

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// …

Sep 8, 2026
CVE-2026-78631
5.3 MEDIUM

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA …

Sep 8, 2026
CVE-2026-78630
6.7 MEDIUM

The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated …

Sep 8, 2026
CVE-2026-78629
5.6 MEDIUM

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. …

Sep 8, 2026
CVE-2026-78622
6.0 MEDIUM

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. …

Sep 8, 2026
CVE-2026-77827
7.1 HIGH

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

Sep 8, 2026
CVE-2026-45220

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-45219

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-30754
8.8 HIGH

A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is …

Sep 8, 2026
CVE-2026-19651
7.4 HIGH

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due …

Sep 8, 2026
CVE-2026-19625
5.3 MEDIUM

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and …

Sep 8, 2026
CVE-2026-86810
7.3 HIGH

A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing …

Sep 8, 2026
CVE-2026-86808
7.3 HIGH

A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation …

Sep 8, 2026
CVE-2026-86806
7.3 HIGH

A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can …

Sep 8, 2026
CVE-2026-86464

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default …

Sep 8, 2026
CVE-2026-85630
6.1 MEDIUM

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where …

Sep 8, 2026
CVE-2026-85485
6.1 MEDIUM

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers …

Sep 8, 2026
CVE-2026-85484
6.1 MEDIUM

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets …

Sep 8, 2026
CVE-2026-84942
8.7 HIGH

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript …

Sep 8, 2026
CVE-2026-84869
9.9 CRITICAL KEV

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in …

Sep 8, 2026
CVE-2026-84197

In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, …

Sep 8, 2026
CVE-2026-82007
7.8 HIGH

Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-82006
7.8 HIGH

Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-82005
7.8 HIGH

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-79905
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2026-78834
8.8 HIGH

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported …

Sep 8, 2026
CVE-2026-78627
7.3 HIGH

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in …

Sep 8, 2026
CVE-2026-78626
8.1 HIGH

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an …

Sep 8, 2026
CVE-2026-78625
6.7 MEDIUM

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during …

Sep 8, 2026
CVE-2026-78624
4.9 MEDIUM

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to …

Sep 8, 2026
CVE-2026-78623
7.7 HIGH

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values …

Sep 8, 2026
CVE-2026-78620
5.9 MEDIUM

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event …

Sep 8, 2026
CVE-2026-78579
6.8 MEDIUM

The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw …

Sep 8, 2026
CVE-2026-78574
7.5 HIGH

The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is …

Sep 8, 2026
CVE-2026-78560
4.8 MEDIUM

The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where …

Sep 8, 2026
CVE-2026-78552
6.0 MEDIUM

The Okta Access Gateway does not apply its Lua directive restriction to the application-level custom configuration field. The field is interpolated directly into the nginx …

Sep 8, 2026
CVE-2026-78550
6.6 MEDIUM

The Okta Access Gateway management console passes user-supplied input to eval() without sanitization during an authenticated administrator SSH session. As a result, the unsanitized input …

Sep 8, 2026
CVE-2026-78545
6.6 MEDIUM

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated …

Sep 8, 2026
CVE-2026-76199
8.6 HIGH

Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-76190
8.6 HIGH

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the …

Sep 8, 2026
CVE-2026-76002
6.1 MEDIUM

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a …

Sep 8, 2026
CVE-2026-76000
6.5 MEDIUM

ColdFusion is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, …

Sep 8, 2026
CVE-2026-75999
8.4 HIGH

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged …

Sep 8, 2026
CVE-2026-75998
7.5 HIGH

ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access …

Sep 8, 2026
CVE-2026-75993
8.5 HIGH

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.