CVE Database

45611+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-59146
7.8 HIGH

Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator …

Jul 21, 2026
CVE-2026-56852
7.5 HIGH

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

Jul 21, 2026
CVE-2026-50759
7.5 HIGH

An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.

Jul 21, 2026
CVE-2026-50758
8.1 HIGH

Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

Jul 21, 2026
CVE-2026-50757
7.8 HIGH

Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

Jul 21, 2026
CVE-2026-50756
7.5 HIGH

An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

Jul 21, 2026
CVE-2026-47667
7.5 HIGH

CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from …

Jul 21, 2026
CVE-2026-46600
7.5 HIGH

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Jul 21, 2026
CVE-2026-30632
7.5 HIGH

Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

Jul 21, 2026
CVE-2026-15957
7.5 HIGH

Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust …

Jul 21, 2026
CVE-2026-64877
8.4 HIGH

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Jul 21, 2026
CVE-2026-63454
7.2 HIGH

An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location …

Jul 21, 2026
CVE-2026-63453
7.2 HIGH

Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary …

Jul 21, 2026
CVE-2026-55084
8.8 HIGH

DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint …

Jul 21, 2026
CVE-2026-47419
8.3 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD …

Jul 21, 2026
CVE-2026-47418
8.1 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD …

Jul 21, 2026
CVE-2026-47417
8.1 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints …

Jul 21, 2026
CVE-2026-47415
8.3 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD …

Jul 21, 2026
CVE-2026-47414
7.6 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints …

Jul 21, 2026
CVE-2026-47412
8.1 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE …

Jul 21, 2026
CVE-2026-44880
8.8 HIGH

A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to …

Jul 21, 2026
CVE-2026-21575
7.1 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code …

Jul 21, 2026
CVE-2026-16493
7.8 HIGH

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when …

Jul 21, 2026
CVE-2026-47409
8.1 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE …

Jul 21, 2026
CVE-2026-47406
8.1 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints …

Jul 21, 2026
CVE-2026-47405
8.8 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any …

Jul 21, 2026
CVE-2026-47399
8.8 HIGH

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization …

Jul 21, 2026
CVE-2026-47398
8.1 HIGH

PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. However, …

Jul 21, 2026
CVE-2026-44907
7.5 HIGH

A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; …

Jul 21, 2026
CVE-2026-15724
8.7 HIGH

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary …

Jul 21, 2026
CVE-2026-64824
8.4 HIGH

Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths …

Jul 21, 2026
CVE-2026-8933
7.8 HIGH

A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution environment for snap …

Jul 21, 2026
CVE-2026-65052
7.5 HIGH

Ninja Forms WordPress plugin version 3.14.8 and prior contains an improper input validation vulnerability that allows unauthenticated attackers to inject arbitrary numeric values into form …

Jul 21, 2026
CVE-2026-59851
8.8 HIGH

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for …

Jul 21, 2026
CVE-2026-15226
8.4 HIGH

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine …

Jul 21, 2026
CVE-2026-16447
7.3 HIGH

A vulnerability has been found in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /web/jquery/uploader/multi_uploadify.php. The manipulation of the argument Filedata[] leads …

Jul 21, 2026
CVE-2026-16445
7.5 HIGH

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as …

Jul 21, 2026
CVE-2026-16409
7.5 HIGH

Invalid pointer in the Security: PSM component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16405
7.5 HIGH

Information disclosure in the Networking: WebSockets component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-16404
7.4 HIGH

Spoofing issue in Firefox for Android. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16401
8.8 HIGH

Privilege escalation in the Data Loss Prevention component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16400
7.5 HIGH

Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16399
7.5 HIGH

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16398
7.5 HIGH

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16396
8.8 HIGH

Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-16391
7.5 HIGH

Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-16386
7.5 HIGH

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16385
7.5 HIGH

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16384
7.5 HIGH

Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16379
8.8 HIGH

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.