CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-79577
9.8 CRITICAL

An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.

Sep 8, 2026
CVE-2026-79576
9.8 CRITICAL

An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

Sep 8, 2026
CVE-2026-79575
7.5 HIGH

The JWT signing secret in yfexam-exam v2.0 is derived from the username and the current month instead of a random server-side key, making the secret …

Sep 8, 2026
CVE-2026-79571
9.1 CRITICAL

Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products …

Sep 8, 2026
CVE-2026-78837
7.5 HIGH

A SQL injection vulnerability in the ap_form_{id} parameter in AppNitro MachForm v30 allows attackers to access sensitive database information via a crafted SQL statement.

Sep 8, 2026
CVE-2026-70614

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-70613

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-61517
7.2 HIGH

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell …

Sep 8, 2026
CVE-2026-61516
9.8 CRITICAL

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to …

Sep 8, 2026
CVE-2026-5729
7.8 HIGH

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user …

Sep 8, 2026
CVE-2026-33197

AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of …

Sep 8, 2026
CVE-2026-18851
8.8 HIGH

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

Sep 8, 2026
CVE-2026-12745
9.8 CRITICAL

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12744
9.8 CRITICAL

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12651
8.8 HIGH

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12650
9.9 CRITICAL

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12648
8.8 HIGH

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12647
9.9 CRITICAL

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12646
9.9 CRITICAL

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12645
9.9 CRITICAL

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Sep 8, 2026
CVE-2026-12387
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 8, 2026
CVE-2026-12285
4.0 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 8, 2026
CVE-2026-11891
5.1 MEDIUM

Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process …

Sep 8, 2026
CVE-2026-0860
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver …

Sep 8, 2026
CVE-2026-0001
4.4 MEDIUM

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 8, 2026
CVE-2026-86644
3.5 LOW

A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save …

Sep 8, 2026
CVE-2026-79379
6.5 MEDIUM

A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers …

Sep 8, 2026
CVE-2026-79378
7.5 HIGH

An issue in the btm_acl_handle() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of …

Sep 8, 2026
CVE-2026-79377
7.5 HIGH

A heap overflow in the a2dp_decoder_sbc.cpp component of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial …

Sep 8, 2026
CVE-2026-79376
8.8 HIGH

An issue in the l2cap_handle_data() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier allows attackers to cause a Denial of …

Sep 8, 2026
CVE-2026-78838
6.5 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allows attackers to execute arbitrary Javascript in the context of the …

Sep 8, 2026
CVE-2026-74239
7.2 HIGH

XenForo before 2.3.13 contains a path traversal vulnerability in the style archive importer on Windows deployments that allows authenticated non-super administrators with style permissions to …

Sep 8, 2026
CVE-2026-73321
6.5 MEDIUM

XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated attackers to cause persistent denial of service by submitting a …

Sep 8, 2026
CVE-2026-73320
6.1 MEDIUM

XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private unfurl records by supplying predictable auto-increment primary key IDs …

Sep 8, 2026
CVE-2026-73319
6.1 MEDIUM

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin …

Sep 8, 2026
CVE-2026-73318
3.8 LOW

XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of …

Sep 8, 2026
CVE-2026-73317
2.7 LOW

XenForo before 2.3.13 contains a missing authorization vulnerability in the ACP cache-rebuild dispatcher that allows limited administrators with only the rebuildCache permission to perform unauthorized …

Sep 8, 2026
CVE-2026-73316
7.5 HIGH

XenForo before 2.3.13 contains a payment replay vulnerability in the PayPal REST payment provider that allows attackers to process the same webhook payload multiple times …

Sep 8, 2026
CVE-2026-73315
8.6 HIGH

XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make …

Sep 8, 2026
CVE-2026-73314
7.5 HIGH

XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by …

Sep 8, 2026
CVE-2026-73313
6.8 MEDIUM

XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user …

Sep 8, 2026
CVE-2026-73312
7.4 HIGH

XenForo before 2.3.13 contains a refresh token replay vulnerability that allows attackers to reuse a refresh token multiple times by exploiting the failure to mark …

Sep 8, 2026
CVE-2026-73311
7.4 HIGH

XenForo before 2.3.13 contains an OAuth2 authorization code reuse vulnerability that allows attackers to obtain unauthorized token pairs by submitting a previously used authorization code. …

Sep 8, 2026
CVE-2026-73310
5.9 MEDIUM

XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any allowlisted redirect URI to bypass redirect URI binding …

Sep 8, 2026
CVE-2026-73309
7.4 HIGH

XenForo before 2.3.13 contains an authentication bypass vulnerability in the OAuth2 token endpoint that allows unauthenticated attackers to obtain valid token pairs by submitting empty …

Sep 8, 2026
CVE-2026-33920
3.5 LOW

A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token. An attacker …

Sep 8, 2026
CVE-2026-33391
5.4 MEDIUM

An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges. An authenticated user with limited privileges …

Sep 8, 2026
CVE-2026-33389
7.5 HIGH

An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's …

Sep 8, 2026
CVE-2026-33388
7.4 HIGH

An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with limited privileges …

Sep 8, 2026
CVE-2026-33387
4.6 MEDIUM

A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.