CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-50349
7.0 HIGH

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Sep 8, 2026
CVE-2026-48707
3.1 LOW

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload …

Sep 8, 2026
CVE-2026-47297
8.1 HIGH

Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-86668
4.3 MEDIUM

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation …

Sep 8, 2026
CVE-2026-86667
4.7 MEDIUM

A weakness has been identified in aircheng-org iWebShop-5 up to 5.15. The affected element is the function member_list of the file controllers/member.php. This manipulation of …

Sep 8, 2026
CVE-2026-86073
7.6 HIGH

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to …

Sep 8, 2026
CVE-2026-84393
8.1 HIGH

A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure …

Sep 8, 2026
CVE-2026-84392
2.7 LOW

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 all versions, FortiPAM 1.7 …

Sep 8, 2026
CVE-2026-84391
6.5 MEDIUM

A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector here>

Sep 8, 2026
CVE-2026-84389
3.1 LOW

A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized …

Sep 8, 2026
CVE-2026-84387
7.2 HIGH

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 …

Sep 8, 2026
CVE-2026-84386
5.1 MEDIUM

A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via <insert attack vector …

Sep 8, 2026
CVE-2026-84385
5.4 MEDIUM

A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 …

Sep 8, 2026
CVE-2026-82533
9.6 CRITICAL

DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host …

Sep 8, 2026
CVE-2026-82514

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-82076
6.5 MEDIUM

An integer overflow in the query planning component of MongoDB Server can allow an authenticated user with ordinary database-level read/write privileges to bypass an internal …

Sep 8, 2026
CVE-2026-82075
7.5 HIGH

An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router …

Sep 8, 2026
CVE-2026-82074
6.5 MEDIUM

MongoDB Server contains an incorrect authorization vulnerability in the aggregation framework. An authenticated user with minimal privileges can craft a specially formatted aggregation request that …

Sep 8, 2026
CVE-2026-82073
6.5 MEDIUM

A security issue in the MongoDB Server aggregation framework allows an authenticated user with limited read privileges to bypass view-level authorization checks and access data …

Sep 8, 2026
CVE-2026-82071
8.1 HIGH

Insufficient validation of storage engine configuration options in MongoDB Server allows an authenticated user with write privileges to supply crafted parameters during collection creation that …

Sep 8, 2026
CVE-2026-82070
6.5 MEDIUM

A security issue in MongoDB Server's diagnostic reporting interface allows an authenticated user with monitoring privileges to access insufficiently protected credentials from concurrent administrative operations. …

Sep 8, 2026
CVE-2026-82069
2.7 LOW

A security issue in MongoDB Server's query statistics serialization on the router allows users with monitoring privileges to access unredacted search query text from other …

Sep 8, 2026
CVE-2026-82068
6.5 MEDIUM

A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable …

Sep 8, 2026
CVE-2026-82067
8.1 HIGH

Improper handling of case sensitivity in the configuration validation component of MongoDB Server may cause the authorization subsystem to remain in a default disabled state …

Sep 8, 2026
CVE-2026-82066
4.3 MEDIUM

A heap out-of-bounds read security issue exists in the query planning component of MongoDB Server. An authenticated user with database read and write privileges can …

Sep 8, 2026
CVE-2026-82065
6.5 MEDIUM

A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of …

Sep 8, 2026
CVE-2026-82064
7.5 HIGH

A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set member. …

Sep 8, 2026
CVE-2026-82063
5.3 MEDIUM

A use-after-free security issue in the cursor management component of MongoDB Server allows an authenticated user to cause a denial of service. Under specific timing …

Sep 8, 2026
CVE-2026-82062
5.5 MEDIUM

A security issue in MongoDB Server allows an authenticated user with elevated internal privileges to bypass a disabled feature gate in the applyOps command by …

Sep 8, 2026
CVE-2026-82061
8.1 HIGH

A use-after-free security issue exists in the server's query execution memory tracking subsystem. An authenticated user with read privileges can trigger a write to freed …

Sep 8, 2026
CVE-2026-82060
5.4 MEDIUM

In MongoDB, insufficient validation of shard key values during document insertion allowed authenticated users to store documents with specially crafted, operator-shaped objects as shard key …

Sep 8, 2026
CVE-2026-82059
5.3 MEDIUM

An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By …

Sep 8, 2026
CVE-2026-82058
6.5 MEDIUM

A flaw in MongoDB's JSON Schema validation error generation code allows an authenticated user with readWrite privileges to crash the mongod server. When a BSON …

Sep 8, 2026
CVE-2026-82057
6.5 MEDIUM

A security issue was discovered in MongoDB where an authenticated user with readWrite privileges could crash the mongod server process. By specifying a custom WiredTiger …

Sep 8, 2026
CVE-2026-82056
5.3 MEDIUM

A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index …

Sep 8, 2026
CVE-2026-82055
6.5 MEDIUM

A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially …

Sep 8, 2026
CVE-2026-82054
6.5 MEDIUM

A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema …

Sep 8, 2026
CVE-2026-82053
8.1 HIGH

A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent …

Sep 8, 2026
CVE-2026-82052
6.5 MEDIUM

The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific …

Sep 8, 2026
CVE-2026-81531

An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related …

Sep 8, 2026
CVE-2026-79570
9.8 CRITICAL

mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information …

Sep 8, 2026
CVE-2026-79569
9.8 CRITICAL

Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information …

Sep 8, 2026
CVE-2026-78997
9.3 CRITICAL

UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context …

Sep 8, 2026
CVE-2026-78230

AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc …

Sep 8, 2026
CVE-2026-78216

AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) …

Sep 8, 2026
CVE-2026-75156
9.1 CRITICAL

Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected …

Sep 8, 2026
CVE-2026-52307
5.4 MEDIUM

An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML …

Sep 8, 2026
CVE-2026-47625
7.5 HIGH

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to …

Sep 8, 2026
CVE-2026-26084
9.9 CRITICAL

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 …

Sep 8, 2026
CVE-2026-22575
4.9 MEDIUM

An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.