CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42138
6.1 MEDIUM

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file …

May 4, 2026
CVE-2026-42092
6.5 MEDIUM

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. …

May 4, 2026
CVE-2026-42091
6.5 MEDIUM

goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to …

May 4, 2026
CVE-2026-42086
4.6 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0, the Command …

May 4, 2026
CVE-2026-42085
4.3 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to versions 6.10.5 and 7.0.0-rc3, …

May 4, 2026
CVE-2026-41572
5.3 MEDIUM

Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a public book, its notes and uploaded assets stay …

May 4, 2026
CVE-2026-42080
4.6 MEDIUM

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary file write vulnerability via `save_generated_slides`. This issue has …

May 4, 2026
CVE-2026-42078
4.6 MEDIUM

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. …

May 4, 2026
CVE-2026-42077
5.2 MEDIUM

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to …

May 4, 2026
CVE-2026-38669
6.1 MEDIUM

wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.

May 4, 2026
CVE-2026-25266
5.5 MEDIUM

Memory corruption while processing IOCTL command when device is in power-save state.

May 4, 2026
CVE-2025-47406
6.1 MEDIUM

Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.

May 4, 2026
CVE-2025-47404
6.5 MEDIUM

Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.

May 4, 2026
CVE-2025-47403
6.5 MEDIUM

Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.

May 4, 2026
CVE-2025-47401
6.5 MEDIUM

Transient DOS when processing target power rate tables during channel configuration.

May 4, 2026
CVE-2026-37458
6.5 MEDIUM

Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying …

May 4, 2026
CVE-2025-70071
5.9 MEDIUM

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXParser.cpp, ParseVectorDataArray()

May 4, 2026
CVE-2026-33523
6.5 MEDIUM

HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend servers. This issue affects Apache HTTP Server: from through 2.4.66. …

May 4, 2026
CVE-2026-33007
5.3 MEDIUM

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in …

May 4, 2026
CVE-2026-33006
4.8 MEDIUM

A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade …

May 4, 2026
CVE-2025-70072
6.5 MEDIUM

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXConverter.cpp, FBXConverter::ConvertMeshMultiMaterial() components

May 4, 2026
CVE-2025-70070
6.5 MEDIUM

An issue in Assimp v.6.0.2 allows a remote attacker to cause a denial of service via the FBXMeshGeometry.cpp, MeshGeometry::MeshGeometry()

May 4, 2026
CVE-2026-34032
5.3 MEDIUM

Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version …

May 4, 2026
CVE-2026-33857
5.3 MEDIUM

Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, …

May 4, 2026
CVE-2026-31205
5.7 MEDIUM

Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function

May 4, 2026
CVE-2026-7746
6.3 MEDIUM

A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file /product_expiry/edit-admin.php. Such manipulation of the …

May 4, 2026
CVE-2026-7745
6.3 MEDIUM

A vulnerability was determined in CodeAstro Online Classroom 1.0. This impacts an unknown function of the file /OnlineClassroom/facultydetails. This manipulation of the argument deleteid causes …

May 4, 2026
CVE-2026-7744
6.3 MEDIUM

A vulnerability was found in CodeAstro Online Classroom 1.0. This affects an unknown function of the file /OnlineClassroom/addnewstudent. The manipulation of the argument fname results …

May 4, 2026
CVE-2026-7743
6.3 MEDIUM

A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the …

May 4, 2026
CVE-2026-7742
6.3 MEDIUM

A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /OnlineClassroom/facultylogin. Executing a manipulation of …

May 4, 2026
CVE-2026-7741
6.3 MEDIUM

A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/studentlogin. Performing a manipulation of the argument sid …

May 4, 2026
CVE-2026-7738
6.3 MEDIUM

A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_document of the file src/mcp-server.ts of the component MCP Interface. The …

May 4, 2026
CVE-2026-7737
5.3 MEDIUM

A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the component …

May 4, 2026
CVE-2026-5335
5.3 MEDIUM

The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to …

May 4, 2026
CVE-2026-20451
6.7 MEDIUM

In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious …

May 4, 2026
CVE-2026-20450
6.5 MEDIUM

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has …

May 4, 2026
CVE-2026-20449
6.5 MEDIUM

In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE …

May 4, 2026
CVE-2026-20448
6.7 MEDIUM

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a …

May 4, 2026
CVE-2026-20447
6.7 MEDIUM

In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a …

May 4, 2026
CVE-2026-7734
5.3 MEDIUM

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 …

May 4, 2026
CVE-2026-7732
6.3 MEDIUM

A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in …

May 4, 2026
CVE-2026-7731
6.3 MEDIUM

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file get_state.php. The manipulation …

May 4, 2026
CVE-2026-7730
6.3 MEDIUM

A weakness has been identified in privsim mcp-test-runner 0.2.0. Impacted is the function child_process.spawn of the file src/index.ts of the component MCP Interface. Executing a …

May 4, 2026
CVE-2026-7729
6.3 MEDIUM

A security flaw has been discovered in pixelsock directus-mcp 1.0.0. This issue affects the function validateUrl of the file index.ts of the component MCP Interface. …

May 4, 2026
CVE-2026-7728
6.3 MEDIUM

A vulnerability was identified in ryanjoachim mcp-rtfm 0.1.0. This vulnerability affects the function get_doc_content/read_doc/update_doc of the component MCP Interface. Such manipulation of the argument docFile …

May 4, 2026
CVE-2026-7725
6.3 MEDIUM

A vulnerability was found in PrefectHQ prefect up to 3.6.25.dev6. Affected by this issue is some unknown functionality of the file src/prefect/runner/storage.py of the component …

May 4, 2026
CVE-2026-7724
5.0 MEDIUM

A vulnerability has been found in PrefectHQ prefect up to 3.6.28.dev1. Affected by this vulnerability is the function validate_restricted_url of the component Webhook/Notification. The manipulation …

May 4, 2026
CVE-2026-7722
5.3 MEDIUM

A vulnerability was detected in PrefectHQ prefect up to 3.6.21. This impacts the function endswith of the file /api/health of the component Health Check API. …

May 4, 2026
CVE-2026-7721
6.3 MEDIUM

A security vulnerability has been detected in Totolink WA300 5.2cu.7112_B20190227. This affects the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument hostTime …

May 4, 2026
CVE-2026-7720
6.3 MEDIUM

A weakness has been identified in Totolink WA300 5.2cu.7112_B20190227. The impacted element is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request …

May 4, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.