CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-4502
6.5 MEDIUM

IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted …

Apr 30, 2026
CVE-2026-41174
6.4 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD …

Apr 30, 2026
CVE-2026-40951
5.5 MEDIUM

CVE-2026-40951 is a memory corruption vulnerability on Secure Access Windows clients prior to 14.50. Attackers with local control of the Windows client can send malformed …

Apr 30, 2026
CVE-2026-40950
6.5 MEDIUM

CVE-2026-40950 is a buffer overflow vulnerability in the Secure Access server prior to 14.50. Attackers with control of a modified client can send a specially …

Apr 30, 2026
CVE-2026-40949
4.4 MEDIUM

CVE-2026-40949 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use …

Apr 30, 2026
CVE-2026-3346
6.4 MEDIUM

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in …

Apr 30, 2026
CVE-2026-3340
6.5 MEDIUM

IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests …

Apr 30, 2026
CVE-2026-33452
5.5 MEDIUM

CVE-2026-33452 is a buffer overflow vulnerability in the Secure Access Windows client prior to 14.50. Attackers with local control of the Windows client can use …

Apr 30, 2026
CVE-2026-33450
5.5 MEDIUM

CVE-2026-33450 is an out of bounds read vulnerability in the Secure Access MacOS client prior to 14.50. Attackers with control of a modified server can …

Apr 30, 2026
CVE-2026-28532
6.5 MEDIUM

FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates …

Apr 30, 2026
CVE-2026-7429
4.6 MEDIUM

SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template …

Apr 30, 2026
CVE-2026-40603
6.5 MEDIUM

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew …

Apr 30, 2026
CVE-2026-35514
6.5 MEDIUM

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the …

Apr 30, 2026
CVE-2026-32148
5.9 MEDIUM

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for dependencies in …

Apr 30, 2026
CVE-2026-3833
6.5 MEDIUM

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints …

Apr 30, 2026
CVE-2026-36766
5.4 MEDIUM

Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting a …

Apr 30, 2026
CVE-2026-36763
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a …

Apr 30, 2026
CVE-2026-36761
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a …

Apr 30, 2026
CVE-2026-36764
5.0 MEDIUM

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

Apr 30, 2026
CVE-2026-36757
4.3 MEDIUM

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Apr 30, 2026
CVE-2026-38940
6.1 MEDIUM

Cross Site Scripting vulnerability in RafyMrX TOKO-ONLINE-ROTI v.1.0 allows a remote attacker to execute arbitrary code via the detail_produk.php component

Apr 30, 2026
CVE-2026-38939
6.1 MEDIUM

Cross Site Scripting vulnerability in andrewtch88 mvc-ecommerce v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the product_catalogue.php component

Apr 30, 2026
CVE-2026-36759
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Apr 30, 2026
CVE-2026-36758
4.3 MEDIUM

A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Apr 30, 2026
CVE-2026-36756
5.4 MEDIUM

A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Apr 30, 2026
CVE-2026-7500
5.4 MEDIUM

When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — …

Apr 30, 2026
CVE-2026-7163
6.1 MEDIUM

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped …

Apr 30, 2026
CVE-2026-7382
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows …

Apr 30, 2026
CVE-2026-5080
5.9 MEDIUM

Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with …

Apr 30, 2026
CVE-2026-1493
5.4 MEDIUM

LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker …

Apr 30, 2026
CVE-2026-31692
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on …

Apr 30, 2026
CVE-2026-6498
5.3 MEDIUM

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 …

Apr 30, 2026
CVE-2026-41016
5.9 MEDIUM

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between …

Apr 30, 2026
CVE-2026-6870
5.5 MEDIUM

GSM RP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6869
5.5 MEDIUM

WebSocket protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6867
5.5 MEDIUM

SMB2 protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6538
5.5 MEDIUM

BEEP protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6537
5.5 MEDIUM

ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6536
5.5 MEDIUM

DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4

Apr 30, 2026
CVE-2026-6535
5.5 MEDIUM

Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6534
5.5 MEDIUM

USB HID protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6533
5.5 MEDIUM

Dissection engine LZ77 decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6532
5.5 MEDIUM

Kismet protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6531
5.5 MEDIUM

SANE protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6530
5.5 MEDIUM

DCP-ETSI protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6529
5.5 MEDIUM

iLBC audio codec crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6528
5.5 MEDIUM

TLS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 allows denial of service

Apr 30, 2026
CVE-2026-6527
5.5 MEDIUM

ASN.1 PER protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026
CVE-2026-6526
5.5 MEDIUM

RTSP protocol dissector crash in Wireshark 4.6.0 to 4.6.4

Apr 30, 2026
CVE-2026-6524
5.5 MEDIUM

MySQL protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service

Apr 30, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.