CVE Database

52310+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2018-25295
6.2 MEDIUM

ObserverIP Scan Tool 1.4.0.1 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string in …

Apr 26, 2026
CVE-2018-25293
6.2 MEDIUM

Prime95 29.4b7 contains a buffer overflow vulnerability in the PrimeNet connection dialog that allows local attackers to crash the application by supplying an excessively long …

Apr 26, 2026
CVE-2018-25292
6.2 MEDIUM

Bome Restorator 1793 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name …

Apr 26, 2026
CVE-2018-25291
6.2 MEDIUM

Project64 2.3.2 contains a buffer overflow vulnerability in the Plugin Directory settings field that allows local attackers to crash the application by supplying an excessively …

Apr 26, 2026
CVE-2018-25290
6.2 MEDIUM

Easyboot 6.6.0 contains a buffer overflow vulnerability in the Replace Text function that allows local attackers to crash the application by supplying an oversized string. …

Apr 26, 2026
CVE-2018-25289
6.2 MEDIUM

Softdisk 3.0.3 contains a buffer overflow vulnerability in the registration code dialog that allows local attackers to crash the application by supplying an oversized string. …

Apr 26, 2026
CVE-2018-25288
6.2 MEDIUM

StyleWriter 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a …

Apr 26, 2026
CVE-2018-25287
5.5 MEDIUM

Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the …

Apr 26, 2026
CVE-2018-25286
6.2 MEDIUM

Easy PhotoResQ 1.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Folder/filename …

Apr 26, 2026
CVE-2018-25285
5.5 MEDIUM

Fathom 2.4 contains a buffer overflow vulnerability in the Authorization Code field that allows local attackers to crash the application by submitting an oversized input …

Apr 26, 2026
CVE-2018-25284
6.2 MEDIUM

HD Tune Pro 5.70 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the …

Apr 26, 2026
CVE-2018-25282
6.2 MEDIUM

Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. …

Apr 26, 2026
CVE-2018-25281
5.5 MEDIUM

iCash 7.6.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload through the Connect to Server …

Apr 26, 2026
CVE-2018-25280
5.5 MEDIUM

Infiltrator Network Security Scanner 4.6 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers …

Apr 26, 2026
CVE-2018-25279
6.2 MEDIUM

jiNa OCR Image to Text 1.0 contains a denial of service vulnerability that allows local attackers to crash the application by processing a malformed PNG …

Apr 26, 2026
CVE-2018-25278
6.2 MEDIUM

PicaJet FX 2.6.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. Attackers …

Apr 26, 2026
CVE-2018-25277
6.2 MEDIUM

PixGPS 1.1.8 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string to the folder path input …

Apr 26, 2026
CVE-2018-25276
5.5 MEDIUM

RoboImport 1.2.0.72 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input to registration fields. Attackers can …

Apr 26, 2026
CVE-2018-25275
6.2 MEDIUM

Faleemi Plus 1.0.2 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying oversized input strings. Attackers can paste a …

Apr 26, 2026
CVE-2018-25274
6.2 MEDIUM

InfraRecorder 0.53 contains a denial of service vulnerability that allows local attackers to crash the application by importing a maliciously crafted text file. Attackers can …

Apr 26, 2026
CVE-2018-25273
6.2 MEDIUM

CrossFont 7.5 contains a buffer overflow vulnerability that allows local attackers to crash the application by submitting an oversized payload in the License Key field. …

Apr 26, 2026
CVE-2018-25264
6.2 MEDIUM

TransMac 12.2 contains a buffer overflow vulnerability in the license key input field that allows local attackers to crash the application by submitting an oversized …

Apr 26, 2026
CVE-2026-7028
4.7 MEDIUM

A security flaw has been discovered in CodeAstro Online Job Portal 1.0. The affected element is an unknown function of the file /admin/jobs-admins/delete-jobs.php of the …

Apr 26, 2026
CVE-2026-7026
4.5 MEDIUM

A vulnerability was determined in D-Link DGS-3420 1.50.018. This issue affects some unknown processing of the component System Information Settings Page. This manipulation of the …

Apr 26, 2026
CVE-2026-7024
5.4 MEDIUM

A flaw has been found in rawchen sims up to 004f783b1db5ecdfad81c8fdc3b34171211112de. Affected by this issue is some unknown functionality of the file sims-master/src/web/servlet/file/DeleteFileServlet.java of the …

Apr 26, 2026
CVE-2026-7023
6.3 MEDIUM

A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/domain/memory/database/service/database_impl.go of the component …

Apr 26, 2026
CVE-2026-7018
5.6 MEDIUM

A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT …

Apr 26, 2026
CVE-2026-42254
4.0 MEDIUM

Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone poisoning because cached data is not directly associated with a query that triggered a response.

Apr 26, 2026
CVE-2026-6994
6.3 MEDIUM

A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the component Query Parameter Handler. …

Apr 25, 2026
CVE-2026-6993
5.3 MEDIUM

A security flaw has been discovered in go-kratos kratos up to 2.9.2. This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux …

Apr 25, 2026
CVE-2026-6991
6.3 MEDIUM

A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component CUID …

Apr 25, 2026
CVE-2026-6989
6.3 MEDIUM

A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet Service. …

Apr 25, 2026
CVE-2026-6985
5.3 MEDIUM

A weakness has been identified in Cesanta Mongoose up to 7.20. This vulnerability affects the function handle_opt of the file /src/net_builtin.c of the component TCP …

Apr 25, 2026
CVE-2026-6984
4.7 MEDIUM

A security flaw has been discovered in AstrBotDevs AstrBot up to 4.22.1. This affects the function create_template of the file astrbot/dashboard/routes/t2i.py of the component Dashboard …

Apr 25, 2026
CVE-2026-6983
4.7 MEDIUM

A vulnerability was identified in pagekit up to 1.0.18. Affected by this issue is some unknown functionality of the file /index.php/admin/system/update/download. The manipulation of the …

Apr 25, 2026
CVE-2026-6982
6.3 MEDIUM

A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file server/Application/Api/Controller/PageController.class.PHP of the component …

Apr 25, 2026
CVE-2026-6981
6.3 MEDIUM

A vulnerability was found in IhateCreatingUserNames2 AiraHub2 up to 3e4b77fd7d48ed811ffe5b8d222068c17c76495e. Affected is the function connect_stream_endpoint/sync_agents of the file AiraHub.py of the component Endpoint. Performing a …

Apr 25, 2026
CVE-2026-6979
6.3 MEDIUM

A flaw has been found in devlikeapro WAHA up to 2026.3.4. This affects an unknown function of the file src/api/media.controller.ts of the component API Request …

Apr 25, 2026
CVE-2026-6978
4.7 MEDIUM

A vulnerability was detected in JiZhiCMS up to 2.5.6. The impacted element is the function htmlspecialchars_decode of the file /index.php/admins/Sys/addcache.html. The manipulation of the argument …

Apr 25, 2026
CVE-2026-31684
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: sched: act_csum: validate nested VLAN headers tcf_csum_act() walks nested VLAN headers directly from skb->data …

Apr 25, 2026
CVE-2026-31681
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_multiport: validate range encoding in checkentry ports_match_v1() treats any non-zero pflags entry as the …

Apr 25, 2026
CVE-2026-31677
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - limit RX SG extraction by receive buffer budget Make af_alg_get_rsgl() limit each …

Apr 25, 2026
CVE-2026-41481
6.5 MEDIUM

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_text_from_url() validated the initial URL using validate_safe_url() but then performed the …

Apr 24, 2026
CVE-2026-41472
6.1 MEDIUM

CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows …

Apr 24, 2026
CVE-2026-6968
5.9 MEDIUM

Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write files outside intended output directories via absolute …

Apr 24, 2026
CVE-2026-6967
5.9 MEDIUM

Missing expiration, hash, and length enforcement in delegated metadata validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users with delegated signing authority to bypass TUF …

Apr 24, 2026
CVE-2026-6966
5.3 MEDIUM

Improper verification of cryptographic signature uniqueness in delegated role validation in awslabs/tough before tough-v0.22.0 allows remote authenticated users to bypass the TUF signature threshold requirement …

Apr 24, 2026
CVE-2026-41427
6.5 MEDIUM

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.5, the clientPrivileges option documents a create action, but the OAuth client creation …

Apr 24, 2026
CVE-2026-41426
6.1 MEDIUM

pretalx is a conference planning tool. Prior to 2026.1.0, an unauthenticated attacker can send arbitrary HTML-rendered emails from a pretalx instance's configured sender address by …

Apr 24, 2026
CVE-2026-41425
5.4 MEDIUM

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in …

Apr 24, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.