CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-38935
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in diskover-community <= 2.3.5 in public/view.php via the doctype parameter

Apr 27, 2026
CVE-2026-30462
4.3 MEDIUM

A path traversal vulnerability in the Blocks module of Daylight Studio FuelCMS v1.5.2 allows attackers to execute a directory traversal.

Apr 27, 2026
CVE-2026-30346
4.3 MEDIUM

An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

Apr 27, 2026
CVE-2026-7135
5.3 MEDIUM

A security flaw has been discovered in GPAC up to 26.03-DEV-rev105-g8f39a1eb3-master. Affected by this vulnerability is the function elng_box_read of the file src/isomedia/box_code_base.c of the …

Apr 27, 2026
CVE-2026-7134
4.7 MEDIUM

A vulnerability was identified in code-projects Online Lot Reservation System 1.0. Affected is an unknown function of the file /edithousepic.php. Such manipulation of the argument …

Apr 27, 2026
CVE-2026-41467
5.4 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the file upload functionality where the checkValidFileName() function fails to restrict HTML and …

Apr 27, 2026
CVE-2026-41466
5.4 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contain a stored cross-site scripting vulnerability in the checkValidHtmlText() function within Security.php that fails to properly sanitize user input by …

Apr 27, 2026
CVE-2026-41465
6.5 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contains a path traversal vulnerability in the log file viewer at dynamicDialog.php where the logname parameter is not validated against …

Apr 27, 2026
CVE-2026-41464
6.5 MEDIUM

ProjeQtor versions 7.0 through 12.4.3 contain a missing authorization vulnerability in the objectDetail.php endpoint that allows authenticated users with guest-level privileges to retrieve sensitive data …

Apr 27, 2026
CVE-2026-7133
4.7 MEDIUM

A vulnerability was determined in code-projects Online Lot Reservation System 1.0. This impacts an unknown function of the file /activity.php. This manipulation of the argument …

Apr 27, 2026
CVE-2026-7132
5.3 MEDIUM

A vulnerability was found in code-projects Online Lot Reservation System up to 1.0. This affects the function readfile of the file /download.php. The manipulation of …

Apr 27, 2026
CVE-2026-40514
5.9 MEDIUM

SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization …

Apr 27, 2026
CVE-2026-7129
4.3 MEDIUM

A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Impacted is an unknown function of the file /index.php?page=categories. Performing a manipulation of …

Apr 27, 2026
CVE-2026-41081
6.5 MEDIUM

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is …

Apr 27, 2026
CVE-2026-40557
4.8 MEDIUM

Improper Certificate Validation via Global SSL Context Downgrade in Apache Storm Prometheus Reporter Versions Affected: from 2.6.3 to 2.8.6 Description: In production deployments where an …

Apr 27, 2026
CVE-2026-7118
6.3 MEDIUM

A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation …

Apr 27, 2026
CVE-2026-7117
6.3 MEDIUM

A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the …

Apr 27, 2026
CVE-2026-7116
4.3 MEDIUM

A security flaw has been discovered in code-projects Employee Management System 1.0. This issue affects some unknown processing of the file 370project/mark.php. Performing a manipulation …

Apr 27, 2026
CVE-2026-5942
5.5 MEDIUM

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.

Apr 27, 2026
CVE-2026-5939
5.5 MEDIUM

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.

Apr 27, 2026
CVE-2026-5938
5.5 MEDIUM

Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial …

Apr 27, 2026
CVE-2026-5937
5.5 MEDIUM

Insufficient parameter verification leads to the occurrence of format errors in files, which will trigger an unhandled "std::invalid_argument" exception, ultimately causing the program to terminate.

Apr 27, 2026
CVE-2026-42410
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) allows DOM-Based XSS.This issue affects TheGem Theme …

Apr 27, 2026
CVE-2026-7115
6.3 MEDIUM

A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID …

Apr 27, 2026
CVE-2026-7114
6.3 MEDIUM

A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID …

Apr 27, 2026
CVE-2026-7113
5.6 MEDIUM

A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. …

Apr 27, 2026
CVE-2026-7112
5.6 MEDIUM

A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY …

Apr 27, 2026
CVE-2026-7109
5.3 MEDIUM

A vulnerability was detected in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /item of the component API Endpoint. …

Apr 27, 2026
CVE-2026-7108
4.3 MEDIUM

A security vulnerability has been detected in code-projects Invoice System in Laravel 1.0. This affects an unknown function. Such manipulation leads to cross-site request forgery. …

Apr 27, 2026
CVE-2026-7107
6.3 MEDIUM

A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation …

Apr 27, 2026
CVE-2026-7102
6.3 MEDIUM

A vulnerability was found in Tenda F456 1.0.0.5. This impacts the function FromWriteFacMac of the file /goform/WriteFacMac of the component httpd. The manipulation of the …

Apr 27, 2026
CVE-2026-7095
4.3 MEDIUM

A vulnerability was identified in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. The manipulation of the argument ID …

Apr 27, 2026
CVE-2026-7093
6.3 MEDIUM

A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the …

Apr 27, 2026
CVE-2026-7092
6.3 MEDIUM

A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile …

Apr 27, 2026
CVE-2026-7091
6.3 MEDIUM

A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User …

Apr 27, 2026
CVE-2026-42371
5.1 MEDIUM

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

Apr 27, 2026
CVE-2026-3008
6.6 MEDIUM

Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.

Apr 27, 2026
CVE-2026-7089
4.3 MEDIUM

A security vulnerability has been detected in code-projects Home Service System 1.0. The impacted element is an unknown function of the file /booking.php of the …

Apr 27, 2026
CVE-2026-7086
4.3 MEDIUM

A vulnerability was identified in HBAI-Ltd Toonflow-app up to 1.1.1. This issue affects the function updateStoryboardUrl of the file replaceUrl.ts of the component Storyboard Export. …

Apr 27, 2026
CVE-2026-7085
5.0 MEDIUM

A vulnerability was determined in HBAI-Ltd Toonflow-app up to 1.1.1. This vulnerability affects the function z.url of the file src/routes/setting/about/downloadApp.ts of the component downloadApp Endpoint. …

Apr 27, 2026
CVE-2026-7084
6.3 MEDIUM

A vulnerability was found in HBAI-Ltd Toonflow-app up to 1.1.1. This affects the function fetch of the file src/routes/setting/vendorConfig/getCodeByLink.ts of the component getCodeByLink Endpoint. The …

Apr 27, 2026
CVE-2026-7083
4.7 MEDIUM

A vulnerability has been found in likeadmin-likeshop likeadmin_php up to 1.9.6. Affected by this issue is the function queryResult of the file server\app\adminapi\lists\tools\DataTableLists.php of the …

Apr 27, 2026
CVE-2026-7071
5.3 MEDIUM

A security vulnerability has been detected in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/user-cvs/. The …

Apr 27, 2026
CVE-2026-33566
4.3 MEDIUM

There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database …

Apr 27, 2026
CVE-2026-7059
5.3 MEDIUM

A vulnerability was found in 666ghj MiroFish up to 0.1.2. This affects the function get_simulation_posts of the file backend/app/api/simulation.py of the component Query Parameter Handler. …

Apr 26, 2026
CVE-2026-7045
6.3 MEDIUM

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the component StandardEvaluationContext/SpelExpressionParser. This …

Apr 26, 2026
CVE-2026-7044
6.3 MEDIUM

A vulnerability was found in GreenCMS up to 2.3. Affected is the function themeadd of the file /index.php?m=admin&c=custom&a=themeadd. The manipulation results in unrestricted upload. The …

Apr 26, 2026
CVE-2026-7043
6.3 MEDIUM

A vulnerability has been found in GreenCMS up to 2.3. This impacts the function pluginAddLocal of the file /index.php?m=admin&c=custom&a=pluginadd. The manipulation leads to unrestricted upload. …

Apr 26, 2026
CVE-2018-25297
6.2 MEDIUM

Wansview 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can inject 2000-byte payloads …

Apr 26, 2026
CVE-2018-25296
5.5 MEDIUM

P10 Central Management Software 1.4.13 contains a buffer overflow vulnerability in the login password field that allows local attackers to crash the application by submitting …

Apr 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.