CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-19713
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-19644
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-19612
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-19479
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-19232
9.9 CRITICAL

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially …

Sep 8, 2026
CVE-2025-64868
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64866
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64854
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64838
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64830
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64618
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64610
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64589
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64588
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64584
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 8, 2026
CVE-2025-64542
5.4 MEDIUM

Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute …

Sep 8, 2026
CVE-2026-86804
5.3 MEDIUM

A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.10. This vulnerability affects the function CPAResource of the file apps/manager-server/internal/http/controller/proxy/handler.go of the component HTTP Handler. …

Sep 8, 2026
CVE-2026-86716
7.3 HIGH

A vulnerability was determined in Cesanta mJS up to 1.26. Affected is the function skip_spaces_and_comments of the file src/mjs_tok.c. Executing a manipulation can lead to …

Sep 8, 2026
CVE-2026-86675
6.3 MEDIUM

A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/us_edit.php. Such manipulation of the argument …

Sep 8, 2026
CVE-2026-86674
6.3 MEDIUM

A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is the function session_start of the file login.php. The …

Sep 8, 2026
CVE-2026-85384

A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an …

Sep 8, 2026
CVE-2026-82537
8.8 HIGH

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between …

Sep 8, 2026
CVE-2026-82536
8.8 HIGH

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute denied shell commands by exploiting the …

Sep 8, 2026
CVE-2026-82004
10.0 CRITICAL

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result …

Sep 8, 2026
CVE-2026-79721

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code …

Sep 8, 2026
CVE-2026-77774
8.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Sep 8, 2026
CVE-2026-77111
8.7 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this …

Sep 8, 2026
CVE-2026-77110
7.6 HIGH

Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature …

Sep 8, 2026
CVE-2026-77109
8.6 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-77108
7.5 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-76202
8.2 HIGH

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access …

Sep 8, 2026
CVE-2026-76201
9.3 CRITICAL

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form …

Sep 8, 2026
CVE-2026-76200
9.3 CRITICAL

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form …

Sep 8, 2026
CVE-2026-69646
8.3 HIGH

Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

Sep 8, 2026
CVE-2026-69642
6.5 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-66308
6.5 MEDIUM

Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-66307
7.5 HIGH

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-66306
6.5 MEDIUM

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-66305
7.1 HIGH

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-66304
7.5 HIGH

Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-66303
6.5 MEDIUM

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-66302
9.8 CRITICAL

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-63523
6.5 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.

Sep 8, 2026
CVE-2026-58941
7.8 HIGH

In multiple functions of iommu.c, there is a possible out of bounds read/write due to improper input validation. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-58874
7.8 HIGH

In multiple functions of SmsController.java, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of …

Sep 8, 2026
CVE-2026-58848
7.0 HIGH

In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58846
7.8 HIGH

In kvm_iommu_map_sg of iommu.c, there is a possible use after free due to a missing permission check. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58839
7.8 HIGH

In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58823
7.8 HIGH

In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege …

Sep 8, 2026
CVE-2026-58822
9.8 CRITICAL

In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.