CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-44602
3.7 LOW

Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.

May 7, 2026
CVE-2026-44601
3.7 LOW

Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.

May 7, 2026
CVE-2026-41663
3.5 LOW

Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire …

May 7, 2026
CVE-2026-41659
2.7 LOW

Admidio is an open-source user management solution. Prior to version 5.0.9, the member assignment DataTables endpoint (members_assignment_data.php) includes hidden profile fields (BIRTHDAY, STREET, CITY, POSTCODE, …

May 7, 2026
CVE-2026-44600
3.7 LOW

Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.

May 7, 2026
CVE-2026-44599
3.7 LOW

Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.

May 7, 2026
CVE-2026-44597
3.7 LOW

Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.

May 7, 2026
CVE-2026-8022
3.1 LOW

Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

May 6, 2026
CVE-2026-8017
3.1 LOW

Side-channel information leakage in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium …

May 6, 2026
CVE-2026-7968
3.1 LOW

Insufficient validation of untrusted input in CORS in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass …

May 6, 2026
CVE-2026-7966
3.1 LOW

Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass …

May 6, 2026
CVE-2026-7965
3.1 LOW

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak …

May 6, 2026
CVE-2026-7959
3.1 LOW

Inappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

May 6, 2026
CVE-2026-7954
3.1 LOW

Race in Shared Storage in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via …

May 6, 2026
CVE-2026-7949
3.1 LOW

Out of bounds read in Skia in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to leak cross-origin …

May 6, 2026
CVE-2026-7945
3.1 LOW

Insufficient validation of untrusted input in COOP in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass …

May 6, 2026
CVE-2026-7944
3.1 LOW

Insufficient validation of untrusted input in Persistent Cache in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to …

May 6, 2026
CVE-2026-7937
3.1 LOW

Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass …

May 6, 2026
CVE-2026-7909
3.1 LOW

Inappropriate implementation in ServiceWorker in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via …

May 6, 2026
CVE-2025-31974
3.9 LOW

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended …

May 6, 2026
CVE-2026-8028
3.7 LOW

A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Performing a …

May 6, 2026
CVE-2025-31984
3.7 LOW

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform …

May 6, 2026
CVE-2025-31983
3.7 LOW

HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This could allow attackers to inject malicious scripts increasing …

May 6, 2026
CVE-2025-31982
3.7 LOW

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk …

May 6, 2026
CVE-2025-31975
2.6 LOW

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and …

May 6, 2026
CVE-2025-31959
3.5 LOW

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location …

May 6, 2026
CVE-2025-31957
2.6 LOW

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

May 6, 2026
CVE-2026-8026
3.7 LOW

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API …

May 6, 2026
CVE-2025-62345
2.7 LOW

HCL BigFix RunBookAI is affected by a Continued availability of Less-Secure “Input Text” Vulnerability . A component contains a security weakness in its input handling …

May 6, 2026
CVE-2025-59854
3.1 LOW

HCL DFXAnalytics is affected by an Insecure Security Header Configuration vulnerability where the application utilizes the outdated X-XSS-Protection header, which could allow an attacker to …

May 6, 2026
CVE-2025-59853
3.1 LOW

HCL DFXAnalytics is affected by an Improper Error Handling vulnerability where the application exposes detailed stack traces in responses, which could allow an attacker to …

May 6, 2026
CVE-2025-59852
3.7 LOW

HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker …

May 6, 2026
CVE-2025-59851
3.7 LOW

HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, which could allow an attacker …

May 6, 2026
CVE-2026-44405
3.4 LOW

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

May 6, 2026
CVE-2026-7847
2.6 LOW

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Uploaded …

May 5, 2026
CVE-2026-7846
2.6 LOW

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component OpenAI-Compatible File …

May 5, 2026
CVE-2026-7845
2.6 LOW

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision …

May 5, 2026
CVE-2026-43529
2.5 LOW

OpenClaw before 2026.4.10 contains a time-of-check-time-of-use vulnerability in the validateScriptFileForShellBleed function that allows local attackers to bypass workspace boundary checks. An attacker with workspace write …

May 5, 2026
CVE-2026-43964
3.7 LOW

Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks …

May 4, 2026
CVE-2026-7740
3.3 LOW

A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit::setFPS of the file tsMuxer/vvc.cpp. Such manipulation of …

May 4, 2026
CVE-2026-7739
3.3 LOW

A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::setFPS of the file /AFLplusplus/tsMuxer_prev/tsMuxer/hevc.cpp. This manipulation of the …

May 4, 2026
CVE-2026-43864
2.5 LOW

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.

May 4, 2026
CVE-2026-43863
3.7 LOW

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

May 4, 2026
CVE-2026-43862
3.7 LOW

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

May 4, 2026
CVE-2026-43861
3.7 LOW

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

May 4, 2026
CVE-2026-43860
3.7 LOW

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

May 4, 2026
CVE-2026-43859
3.7 LOW

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

May 4, 2026
CVE-2026-7689
3.7 LOW

A security flaw has been discovered in Dolibarr ERP CRM up to 23.0.2. This vulnerability affects the function dol_verifyHash in the library htdocs/core/lib/security.lib.php of the …

May 3, 2026
CVE-2026-7677
3.5 LOW

A vulnerability was determined in kerwincui FastBee up to 1.2.1. The impacted element is the function Add of the file springboot/fastbee-admin/src/main/java/com/fastbee/web/controller/system/SysNoticeController.java of the component System …

May 3, 2026
CVE-2026-7671
3.7 LOW

A vulnerability has been found in CodeWise Tornet Scooter Mobile App 4.75 on iOS/Android. The impacted element is an unknown function of the file /TwoFactor. …

May 3, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.