CVE Database

52018+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-61718
5.4 MEDIUM

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). From 1.6.2 until 1.6.12, the BunkerWeb web UI BiscuitMiddleware authorization bypass list included the /cache/ …

Jul 16, 2026
CVE-2026-60140
6.1 MEDIUM

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This can …

Jul 16, 2026
CVE-2026-47089
4.3 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call …

Jul 16, 2026
CVE-2026-47085
4.0 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a …

Jul 16, 2026
CVE-2026-47084
6.5 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the …

Jul 16, 2026
CVE-2026-47083
4.3 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated …

Jul 16, 2026
CVE-2026-47082
5.4 MEDIUM

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script …

Jul 16, 2026
CVE-2026-46514
6.5 MEDIUM

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plaintext password and fm_add_extension in Tools/AddExtension.php:172 returned …

Jul 16, 2026
CVE-2026-46404
6.8 MEDIUM

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. …

Jul 16, 2026
CVE-2026-46378
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune …

Jul 16, 2026
CVE-2026-46377
6.2 MEDIUM

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in …

Jul 16, 2026
CVE-2026-46338
4.3 MEDIUM

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in …

Jul 16, 2026
CVE-2026-46341
6.1 MEDIUM

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior …

Jul 16, 2026
CVE-2026-44968
6.3 MEDIUM

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the …

Jul 16, 2026
CVE-2026-15945
4.3 MEDIUM

A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated …

Jul 16, 2026
CVE-2026-15737
5.7 MEDIUM

AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended …

Jul 16, 2026
CVE-2026-6511
5.5 MEDIUM

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated …

Jul 16, 2026
CVE-2026-55548
4.3 MEDIUM

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request …

Jul 16, 2026
CVE-2026-50012
5.5 MEDIUM

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in …

Jul 16, 2026
CVE-2026-47729
6.5 MEDIUM

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway …

Jul 16, 2026
CVE-2026-45795
5.3 MEDIUM

The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner …

Jul 16, 2026
CVE-2026-45612
5.5 MEDIUM

rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure …

Jul 16, 2026
CVE-2026-44596
6.5 MEDIUM

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, …

Jul 16, 2026
CVE-2026-44595
4.3 MEDIUM

Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required …

Jul 16, 2026
CVE-2026-10590
4.4 MEDIUM

A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.

Jul 16, 2026
CVE-2026-10589
6.0 MEDIUM

A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

Jul 16, 2026
CVE-2026-10588
4.4 MEDIUM

A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

Jul 16, 2026
CVE-2026-10587
6.0 MEDIUM

A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

Jul 16, 2026
CVE-2025-45870
6.5 MEDIUM

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path …

Jul 16, 2026
CVE-2026-63082
5.4 MEDIUM

Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the …

Jul 16, 2026
CVE-2026-63081
5.4 MEDIUM

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious …

Jul 16, 2026
CVE-2026-57205
4.3 MEDIUM

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> …

Jul 16, 2026
CVE-2026-55440
6.5 MEDIUM

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, …

Jul 16, 2026
CVE-2026-54568
4.3 MEDIUM

Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a …

Jul 16, 2026
CVE-2026-56456
5.3 MEDIUM

HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory …

Jul 16, 2026
CVE-2026-56455
5.3 MEDIUM

HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input …

Jul 16, 2026
CVE-2026-56454
5.9 MEDIUM

HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic …

Jul 16, 2026
CVE-2026-56453
5.5 MEDIUM

HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP …

Jul 16, 2026
CVE-2026-9494
5.5 MEDIUM

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During …

Jul 16, 2026
CVE-2026-12391
5.0 MEDIUM

An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file …

Jul 16, 2026
CVE-2024-58360
6.5 MEDIUM

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with …

Jul 16, 2026
CVE-2026-35148
6.3 MEDIUM

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another …

Jul 16, 2026
CVE-2026-35146
6.3 MEDIUM

HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could …

Jul 16, 2026
CVE-2026-15727
4.9 MEDIUM

The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 …

Jul 16, 2026
CVE-2026-15651
4.9 MEDIUM

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, …

Jul 16, 2026
CVE-2026-15610
4.3 MEDIUM

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 16, 2026
CVE-2026-15407
4.3 MEDIUM

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin …

Jul 16, 2026
CVE-2026-15350
4.3 MEDIUM

The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the …

Jul 16, 2026
CVE-2026-15324
4.4 MEDIUM

The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter …

Jul 16, 2026
CVE-2026-15106
5.3 MEDIUM

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.