CVE Database

45611+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-16378
7.5 HIGH

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16376
7.5 HIGH

Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16374
7.5 HIGH

Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-16373
7.5 HIGH

Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

Jul 21, 2026
CVE-2026-16372
8.8 HIGH

Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16371
8.8 HIGH

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-16366
8.8 HIGH

Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16365
8.8 HIGH

Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Jul 21, 2026
CVE-2026-16362
8.8 HIGH

Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-16354
7.5 HIGH

Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Jul 21, 2026
CVE-2026-60080
7.3 HIGH

Use After Free vulnerability in the Rust deserialization logic of Apache Fory. This issue affects Apache Fory from 0.13.0 through 1.3.0. A crafted Fory payload …

Jul 21, 2026
CVE-2026-1771
7.2 HIGH

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all versions up …

Jul 21, 2026
CVE-2026-3183
7.1 HIGH

Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.

Jul 21, 2026
CVE-2026-8082
7.5 HIGH

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce order submission, allowing unauthenticated …

Jul 21, 2026
CVE-2026-11767
8.8 HIGH

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the …

Jul 21, 2026
CVE-2026-6952
7.2 HIGH

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an authenticated attacker …

Jul 21, 2026
CVE-2026-16332
7.3 HIGH

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results …

Jul 21, 2026
CVE-2026-16331
7.3 HIGH

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious …

Jul 21, 2026
CVE-2026-16330
7.3 HIGH

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument …

Jul 21, 2026
CVE-2026-16329
7.3 HIGH

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads …

Jul 21, 2026
CVE-2026-55833
7.5 HIGH

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY header decoding continues inflating zlib-compressed …

Jul 21, 2026
CVE-2026-55831
7.5 HIGH

Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY SETTINGS decoder accepts a peer-declared …

Jul 21, 2026
CVE-2026-16327
7.3 HIGH

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a manipulation of the argument File …

Jul 21, 2026
CVE-2026-15905
7.8 HIGH

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium …

Jul 20, 2026
CVE-2026-15904
8.8 HIGH

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific …

Jul 20, 2026
CVE-2026-15903
8.8 HIGH

Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox …

Jul 20, 2026
CVE-2026-15902
8.8 HIGH

Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

Jul 20, 2026
CVE-2026-64624
7.8 HIGH

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. …

Jul 20, 2026
CVE-2026-55550
7.1 HIGH

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal application server actions restrict product creation, update, …

Jul 20, 2026
CVE-2026-55544
7.6 HIGH

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write operations over the network using …

Jul 20, 2026
CVE-2026-51031
7.5 HIGH

FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information

Jul 20, 2026
CVE-2026-47255
8.2 HIGH

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to …

Jul 20, 2026
CVE-2026-16324
7.3 HIGH

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation …

Jul 20, 2026
CVE-2024-51316
7.5 HIGH

The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName

Jul 20, 2026
CVE-2026-56624
7.3 HIGH

Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation …

Jul 20, 2026
CVE-2026-56623
7.1 HIGH

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server …

Jul 20, 2026
CVE-2026-56452
7.5 HIGH

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of …

Jul 20, 2026
CVE-2026-47198
8.5 HIGH

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, …

Jul 20, 2026
CVE-2026-47130
7.1 HIGH

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact …

Jul 20, 2026
CVE-2026-47129
8.1 HIGH

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js …

Jul 20, 2026
CVE-2026-44508
8.1 HIGH

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's compressed-token decoder …

Jul 20, 2026
CVE-2026-53593
8.8 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads …

Jul 20, 2026
CVE-2026-53591
8.6 HIGH

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into …

Jul 20, 2026
CVE-2026-64619
7.5 HIGH

FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and …

Jul 20, 2026
CVE-2026-64194
7.5 HIGH

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into …

Jul 20, 2026
CVE-2026-63771
7.1 HIGH

Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header …

Jul 20, 2026
CVE-2026-63770
7.5 HIGH

Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary …

Jul 20, 2026
CVE-2026-63769
7.7 HIGH

Huginn through 2022.08.18 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by …

Jul 20, 2026
CVE-2026-63731
7.7 HIGH

HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a …

Jul 20, 2026
CVE-2026-63108
8.8 HIGH

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions …

Jul 20, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.