CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-41526
6.5 MEDIUM

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does …

Apr 28, 2026
CVE-2026-41525
6.5 MEDIUM

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's …

Apr 28, 2026
CVE-2026-40966
5.9 MEDIUM

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter …

Apr 28, 2026
CVE-2026-7230
4.3 MEDIUM

A vulnerability was found in SourceCodester Safety Anger Pad 1.0. The affected element is an unknown function. The manipulation of the argument angerDisplay results in …

Apr 28, 2026
CVE-2026-7229
6.3 MEDIUM

A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing …

Apr 28, 2026
CVE-2026-5306
5.4 MEDIUM

The Check & Log Email WordPress plugin before 2.0.13 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks …

Apr 28, 2026
CVE-2026-40356
5.9 MEDIUM

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is an integer underflow and resultant out-of-bounds read if an application calls gss_accept_sec_context() on a system …

Apr 28, 2026
CVE-2026-6809
6.4 MEDIUM

The Social Post Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Threads embed handler in all versions up to, and including, …

Apr 28, 2026
CVE-2026-6725
6.4 MEDIUM

The WPC Smart Messages for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcsm_text_rotator` shortcode in all …

Apr 28, 2026
CVE-2026-6551
6.4 MEDIUM

The Timeline Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'titleTag' attribute of the timeline-blocks/tb-timeline-blocks block in all versions …

Apr 28, 2026
CVE-2026-42510
6.6 MEDIUM

OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

Apr 28, 2026
CVE-2026-40355
5.9 MEDIUM

In MIT Kerberos 5 (aka krb5) before 1.22.3, there is a NULL pointer dereference if an application calls gss_accept_sec_context() on a system with a NegoEx …

Apr 28, 2026
CVE-2026-7217
5.3 MEDIUM

A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the file packages/mcp-office/src/index.ts of the …

Apr 28, 2026
CVE-2026-0711
6.8 MEDIUM

A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.1)C0 could allow an authenticated, adjacent attacker with administrator privileges …

Apr 28, 2026
CVE-2026-32649
6.8 MEDIUM

A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.

Apr 28, 2026
CVE-2026-7200
4.3 MEDIUM

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /index.php?page=types. …

Apr 28, 2026
CVE-2026-7196
6.3 MEDIUM

A security vulnerability has been detected in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /guestdetails. Such manipulation of the argument …

Apr 28, 2026
CVE-2026-41372
5.8 MEDIUM

OpenClaw before 2026.4.2 fails to normalize trailing-dot localhost hosts in remote CDP discovery responses, allowing bypass of loopback protections. Attackers can craft hostile discovery responses …

Apr 28, 2026
CVE-2026-41370
6.5 MEDIUM

OpenClaw before 2026.3.31 contains a path traversal vulnerability in ACP dispatch that allows attackers to read arbitrary files by manipulating inbound channel attachment paths. Remote …

Apr 28, 2026
CVE-2026-41369
6.5 MEDIUM

OpenClaw before 2026.3.31 contains insufficient environment variable sanitization in host exec operations, failing to filter package, registry, Docker, compiler, and TLS override variables. Attackers can …

Apr 28, 2026
CVE-2026-41368
6.5 MEDIUM

OpenClaw before 2026.3.28 contains an environment variable disclosure vulnerability in the jq safe-bin policy that fails to block the $ENV filter. Attackers can bypass safe-bin …

Apr 28, 2026
CVE-2026-41367
5.0 MEDIUM

OpenClaw versions 2026.2.14 through 2026.3.24 fail to consistently apply guild and channel policy gates to Discord button and component interactions. Attackers can trigger privileged component …

Apr 28, 2026
CVE-2026-41366
5.5 MEDIUM

OpenClaw before 2026.3.31 contains a local roots self-whitelisting vulnerability in appendLocalMediaParentRoots that allows model-initiated arbitrary host file read. Attackers can exploit improper media parent directory …

Apr 28, 2026
CVE-2026-41365
5.4 MEDIUM

OpenClaw before 2026.3.31 contains a sender allowlist bypass vulnerability in MS Teams thread history fetched via Graph API. Attackers can retrieve thread messages that should …

Apr 28, 2026
CVE-2026-41363
5.3 MEDIUM

OpenClaw versions 2026.2.6 through 2026.3.24 contain a path traversal vulnerability in the Feishu extension resolveUploadInput function that bypasses file-system sandbox restrictions. Attackers can exploit improper …

Apr 28, 2026
CVE-2026-41362
4.3 MEDIUM

OpenClaw versions 2026.2.19 before 2026.3.31 contain an improper cache isolation vulnerability in the Zalo webhook replay-dedupe mechanism that is shared across authenticated webhook targets. Attackers …

Apr 28, 2026
CVE-2026-40977
4.7 MEDIUM

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the …

Apr 28, 2026
CVE-2026-40975
4.8 MEDIUM

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as …

Apr 28, 2026
CVE-2026-40974
5.0 MEDIUM

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), …

Apr 28, 2026
CVE-2026-7183
5.3 MEDIUM

A vulnerability has been found in aligungr UERANSIM up to 3.2.7. The affected element is the function rls::DecodeRlsMessage in the library src/lib/rls/rls_pdu.cpp of the component …

Apr 27, 2026
CVE-2026-7179
5.3 MEDIUM

A security vulnerability has been detected in OSPG binwalk up to 2.4.3. This vulnerability affects the function read_null_terminated_string of the file src/binwalk/plugins/winceextract.py of the component …

Apr 27, 2026
CVE-2026-40971
5.0 MEDIUM

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot …

Apr 27, 2026
CVE-2026-29971
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in WebFileSys version before 2.32.0 and fixed in v.2.32.0. User-controlled input is reflected into HTML and JavaScript contexts …

Apr 27, 2026
CVE-2026-7150
6.3 MEDIUM

A vulnerability was found in dh1011 auto-favicon up to f189116a9259950c2393f114dbcb94dde0ad864b. This issue affects the function generate_favicon_from_url of the file src/auto_favicon/server.py of the component MCP Tool. …

Apr 27, 2026
CVE-2026-7148
6.3 MEDIUM

A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument …

Apr 27, 2026
CVE-2026-40970
5.0 MEDIUM

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot …

Apr 27, 2026
CVE-2026-35902
6.2 MEDIUM

The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with …

Apr 27, 2026
CVE-2026-35901
4.4 MEDIUM

A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly …

Apr 27, 2026
CVE-2026-32655
5.3 MEDIUM

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit …

Apr 27, 2026
CVE-2021-36438
6.5 MEDIUM

SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

Apr 27, 2026
CVE-2026-7145
5.4 MEDIUM

A weakness has been identified in mettle sendportal up to 3.0.1. Affected is the function destroy of the file app/Http/Controllers/Workspaces/WorkspaceInvitationsController.php of the component Invitation Handler. …

Apr 27, 2026
CVE-2026-7144
4.3 MEDIUM

A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation …

Apr 27, 2026
CVE-2026-7143
6.3 MEDIUM

A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation …

Apr 27, 2026
CVE-2026-31691
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igb: remove napi_synchronize() in igb_down() When an AF_XDP zero-copy application terminates abruptly (e.g., kill -9), …

Apr 27, 2026
CVE-2026-31689
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: EDAC/mc: Fix error path ordering in edac_mc_alloc() When the mci->pvt_info allocation in edac_mc_alloc() fails, the …

Apr 27, 2026
CVE-2026-31687
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpio: omap: do not register driver in probe() Commit 11a78b794496 ("ARM: OMAP: MPUIO wake updates") …

Apr 27, 2026
CVE-2026-25908
6.7 MEDIUM

Dell Alienware Command Center (AWCC), versions prior to 6.13.8.0, contain an Execution with Unnecessary Privileges vulnerability in the AWCC. A low privileged attacker with local …

Apr 27, 2026
CVE-2026-7142
6.3 MEDIUM

A vulnerability was determined in Wooey up to 0.13.2. The impacted element is the function add_or_update_script of the file wooey/api/scripts.py of the component API Endpoint. …

Apr 27, 2026
CVE-2026-7141
5.6 MEDIUM

A vulnerability was found in vllm up to 0.19.0. The affected element is the function has_mamba_layers of the file vllm/v1/kv_cache_interface.py of the component KV Block …

Apr 27, 2026
CVE-2026-38936
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/selectindices.php via the namecontains parameter

Apr 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.