CVE Database

45611+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-62309
7.5 HIGH

CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin …

Jul 16, 2026
CVE-2026-62290
7.3 HIGH

cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the process of obtaining, renewing and using those certificates. From 1.18.0 …

Jul 16, 2026
CVE-2026-61389
7.0 HIGH

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in …

Jul 16, 2026
CVE-2026-60063
7.0 HIGH

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in …

Jul 16, 2026
CVE-2026-49998
8.2 HIGH

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verification could reuse a key for one allowed issuer to …

Jul 16, 2026
CVE-2026-44982
7.2 HIGH

CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRequestFromRequest allocated a request body buffer from max(r.ContentLength, 0), so HTTP/1.1 requests using …

Jul 16, 2026
CVE-2026-15352
7.5 HIGH

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation …

Jul 16, 2026
CVE-2026-46513
7.4 HIGH

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by Tools/CreateApiToken.php:33-36 as raw bin2hex(random_bytes(32)) strings in …

Jul 16, 2026
CVE-2026-46353
8.1 HIGH

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling …

Jul 16, 2026
CVE-2026-46351
8.1 HIGH

BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutton/web/controllers/ApiController.groovy, allowing a session …

Jul 16, 2026
CVE-2026-46336
7.1 HIGH

Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated …

Jul 16, 2026
CVE-2021-27137
8.1 HIGH KEV

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send …

Jul 16, 2026
CVE-2026-9046
7.0 HIGH

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when …

Jul 16, 2026
CVE-2026-63088
8.6 HIGH

stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address …

Jul 16, 2026
CVE-2026-63086
8.6 HIGH

text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the …

Jul 16, 2026
CVE-2026-63085
8.8 HIGH

Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field …

Jul 16, 2026
CVE-2026-45576
7.5 HIGH

zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such …

Jul 16, 2026
CVE-2026-45367
7.5 HIGH

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular …

Jul 16, 2026
CVE-2026-45325
8.2 HIGH

Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts …

Jul 16, 2026
CVE-2026-13401
7.5 HIGH

XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor …

Jul 16, 2026
CVE-2026-13397
7.5 HIGH

HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor …

Jul 16, 2026
CVE-2026-13104
7.3 HIGH

A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary …

Jul 16, 2026
CVE-2026-13103
7.3 HIGH

A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to …

Jul 16, 2026
CVE-2026-59867
7.1 HIGH

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local …

Jul 16, 2026
CVE-2026-57206
8.6 HIGH

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including …

Jul 16, 2026
CVE-2026-53598
7.5 HIGH

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved …

Jul 16, 2026
CVE-2025-45868
8.8 HIGH

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via …

Jul 16, 2026
CVE-2026-59862
7.5 HIGH

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions …

Jul 16, 2026
CVE-2026-59861
7.5 HIGH

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings …

Jul 16, 2026
CVE-2026-5674
8.8 HIGH

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio …

Jul 16, 2026
CVE-2026-63306
8.6 HIGH

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or …

Jul 16, 2026
CVE-2026-63305
8.1 HIGH

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without …

Jul 16, 2026
CVE-2026-63304
8.1 HIGH

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers …

Jul 16, 2026
CVE-2026-35149
8.2 HIGH

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting …

Jul 16, 2026
CVE-2026-35147
8.2 HIGH

HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific …

Jul 16, 2026
CVE-2026-7543
7.2 HIGH

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient …

Jul 16, 2026
CVE-2026-15103
8.8 HIGH

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update …

Jul 16, 2026
CVE-2026-15008
8.1 HIGH

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file …

Jul 16, 2026
CVE-2026-15005
8.8 HIGH

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing …

Jul 16, 2026
CVE-2026-13741
8.8 HIGH

The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This …

Jul 16, 2026
CVE-2026-12978
7.1 HIGH

The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX …

Jul 16, 2026
CVE-2026-12585
8.1 HIGH

The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting …

Jul 16, 2026
CVE-2026-12525
8.8 HIGH

The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with …

Jul 16, 2026
CVE-2026-53366
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch …

Jul 16, 2026
CVE-2026-13042
7.2 HIGH

The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to …

Jul 16, 2026
CVE-2026-21729
7.5 HIGH

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Jul 16, 2026
CVE-2026-12753
7.5 HIGH

The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter …

Jul 16, 2026
CVE-2026-48863
7.5 HIGH

A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA …

Jul 16, 2026
CVE-2026-3842
7.8 HIGH

A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This …

Jul 16, 2026
CVE-2026-23538
7.5 HIGH

A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening …

Jul 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.