CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-90704
6.6 MEDIUM

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument …

Sep 14, 2026
CVE-2026-68570
6.5 MEDIUM

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in …

Sep 14, 2026
CVE-2026-90700
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of …

Sep 14, 2026
CVE-2026-90698
5.3 MEDIUM

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The …

Sep 14, 2026
CVE-2026-90697
4.3 MEDIUM

A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID …

Sep 14, 2026
CVE-2026-89321
4.3 MEDIUM

Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the …

Sep 14, 2026
CVE-2026-88932
5.3 MEDIUM

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes …

Sep 14, 2026
CVE-2026-90688
6.5 MEDIUM

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule …

Sep 14, 2026
CVE-2026-85125
5.4 MEDIUM

The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage …

Sep 14, 2026
CVE-2026-82796
5.4 MEDIUM

SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker …

Sep 14, 2026
CVE-2026-82795
5.4 MEDIUM

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be …

Sep 14, 2026
CVE-2026-82792
5.2 MEDIUM

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be …

Sep 14, 2026
CVE-2026-82790
5.4 MEDIUM

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed …

Sep 14, 2026
CVE-2026-82788
6.1 MEDIUM

Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82786
6.3 MEDIUM

Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a …

Sep 14, 2026
CVE-2026-82785
4.3 MEDIUM

Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker …

Sep 14, 2026
CVE-2026-82784
6.5 MEDIUM

Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which …

Sep 14, 2026
CVE-2026-82783
4.2 MEDIUM

Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product …

Sep 14, 2026
CVE-2026-82782
4.3 MEDIUM

Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) …

Sep 14, 2026
CVE-2026-82781
5.4 MEDIUM

Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82778
4.3 MEDIUM

An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated …

Sep 14, 2026
CVE-2026-82776
6.1 MEDIUM

Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82775
4.3 MEDIUM

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this …

Sep 14, 2026
CVE-2026-82773
6.1 MEDIUM

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed …

Sep 14, 2026
CVE-2026-82771
5.4 MEDIUM

Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82769
5.4 MEDIUM

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82767
5.2 MEDIUM

Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Sep 14, 2026
CVE-2026-82764
4.3 MEDIUM

Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended …

Sep 14, 2026
CVE-2026-82763
5.4 MEDIUM

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on …

Sep 14, 2026
CVE-2024-23176
5.4 MEDIUM

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

Sep 14, 2026
CVE-2023-51769
6.1 MEDIUM

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

Sep 14, 2026
CVE-2023-50462
5.3 MEDIUM

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier …

Sep 14, 2026
CVE-2023-50460
5.4 MEDIUM

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions …

Sep 14, 2026
CVE-2023-50459
5.4 MEDIUM

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An …

Sep 14, 2026
CVE-2026-90687
6.3 MEDIUM

A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation …

Sep 14, 2026
CVE-2026-90686
5.3 MEDIUM

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results …

Sep 14, 2026
CVE-2023-46035
5.9 MEDIUM

The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.

Sep 14, 2026
CVE-2023-45023
4.2 MEDIUM

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

Sep 14, 2026
CVE-2023-40772
4.3 MEDIUM

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

Sep 14, 2026
CVE-2026-90682
5.3 MEDIUM

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP …

Sep 14, 2026
CVE-2023-34854
6.6 MEDIUM

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

Sep 14, 2026
CVE-2023-29377
6.6 MEDIUM

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is …

Sep 14, 2026
CVE-2026-90621
6.3 MEDIUM

A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the file src/hackingBuddyGPT/extensions/ssh_run_command.py. Such manipulation leads to os command …

Sep 14, 2026
CVE-2026-90615
4.3 MEDIUM

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation …

Sep 14, 2026
CVE-2026-90614
6.3 MEDIUM

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the …

Sep 14, 2026
CVE-2026-33964
6.4 MEDIUM

An issue was discovered in camera in Samsung Mobile Processor Exynos 1580 and 2500. An untrusted pointer dereference occurs when a malformed message is sent …

Sep 14, 2026
CVE-2026-33957
4.2 MEDIUM

An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and …

Sep 14, 2026
CVE-2026-23792
4.0 MEDIUM

An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, …

Sep 14, 2026
CVE-2026-23791
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability …

Sep 14, 2026
CVE-2026-23790
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in …

Sep 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.