CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-79603
4.3 MEDIUM

x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued by Xen …

Sep 8, 2026
CVE-2026-79602
8.8 HIGH

A guest with a PCI device assigned that has at least a BAR on the IO port space can trigger a BUG() in Xen.

Sep 8, 2026
CVE-2026-77106
8.8 HIGH

Cvlaunchd contained a missing authorization issue affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command …

Sep 8, 2026
CVE-2026-77105
8.8 HIGH

CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.

Sep 8, 2026
CVE-2026-77104
7.5 HIGH

CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77103
7.5 HIGH

CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77102
7.5 HIGH

CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77101
7.5 HIGH

CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.

Sep 8, 2026
CVE-2026-77098
9.8 CRITICAL

Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

Sep 8, 2026
CVE-2026-77097
8.2 HIGH

Private Metrics Server contained a missing authentication condition affecting metrics upload functionality and service availability. Software customers upgrade to resolved maintenance release. Update Private Metrics …

Sep 8, 2026
CVE-2026-77092
9.8 CRITICAL

Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.

Sep 8, 2026
CVE-2026-77091
7.8 HIGH

DataCube contained a path traversal issue affecting security feature enforcement. Software customers upgrade to resolved maintenance release. Update Content Extractor and Index Store.

Sep 8, 2026
CVE-2026-77089
9.8 CRITICAL

Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.

Sep 8, 2026
CVE-2026-75021
8.1 HIGH

fastify-cli starts the Node.js Inspector when a debug flag is used, but it ignores the explicit bind address the user supplies and binds the Inspector …

Sep 8, 2026
CVE-2026-62437
6.5 MEDIUM

When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assigned to guests, and the associated …

Sep 8, 2026
CVE-2026-19203

A client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret different request boundaries, …

Sep 8, 2026
CVE-2026-12611

A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be …

Sep 8, 2026
CVE-2026-11573

Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per …

Sep 8, 2026
CVE-2026-86714
5.4 MEDIUM

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply …

Sep 8, 2026
CVE-2026-86713
7.1 HIGH

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter …

Sep 8, 2026
CVE-2026-86712
8.8 HIGH

SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled desktop renderer. …

Sep 8, 2026
CVE-2026-86711
7.4 HIGH

electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side script execution can invoke …

Sep 8, 2026
CVE-2026-80219
8.7 HIGH

A flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and …

Sep 8, 2026
CVE-2026-78234
9.9 CRITICAL

A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint …

Sep 8, 2026
CVE-2026-77968
8.2 HIGH

A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime …

Sep 8, 2026
CVE-2026-76931
6.4 MEDIUM

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 3.3.205 …

Sep 8, 2026
CVE-2026-74860
8.5 HIGH

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing …

Sep 8, 2026
CVE-2026-3174
7.5 HIGH

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth …

Sep 8, 2026
CVE-2026-2520
5.4 MEDIUM

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Sep 8, 2026
CVE-2026-18021
6.5 MEDIUM

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up …

Sep 8, 2026
CVE-2026-17509
6.5 MEDIUM

The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter in all versions up to, and including, 4.9.5 …

Sep 8, 2026
CVE-2026-16502
8.8 HIGH

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 …

Sep 8, 2026
CVE-2026-12230
6.4 MEDIUM

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'layout_custom_css' parameter …

Sep 8, 2026
CVE-2026-77654

Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, 64 bit allows Privilege Escalation and Parameter Injection. A local user …

Sep 8, 2026
CVE-2026-19614

The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue affects NanoXML: 2.2.3.

Sep 8, 2026
CVE-2026-9331
7.1 HIGH

The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service …

Sep 8, 2026
CVE-2026-86590

In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP GET request with …

Sep 8, 2026
CVE-2026-85400

Backend administrators without system maintainer privileges were able to schedule any of the configuration:read, configuration:set, and configuration:show commands. This allowed them to modify arbitrary system …

Sep 8, 2026
CVE-2026-77132

It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization checks. This allowed authenticated, low-privileged backend users …

Sep 8, 2026
CVE-2026-86597
6.5 MEDIUM

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, …

Sep 8, 2026
CVE-2026-86550
6.5 MEDIUM

NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This results in a universal …

Sep 8, 2026
CVE-2026-74859
6.8 MEDIUM

The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files …

Sep 8, 2026
CVE-2026-71377
9.8 CRITICAL

Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through …

Sep 8, 2026
CVE-2026-71376
9.8 CRITICAL

OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through …

Sep 8, 2026
CVE-2026-67367
8.6 HIGH

A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions …

Sep 8, 2026
CVE-2026-62654
6.8 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during …

Sep 8, 2026
CVE-2026-62653
6.8 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the …

Sep 8, 2026
CVE-2026-62652
5.3 MEDIUM

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. …

Sep 8, 2026
CVE-2026-62650
8.8 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing …

Sep 8, 2026
CVE-2026-62649
7.5 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.