CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-62648
7.5 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not …

Sep 8, 2026
CVE-2026-62647
7.4 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session …

Sep 8, 2026
CVE-2026-62646
7.4 HIGH

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in …

Sep 8, 2026
CVE-2026-62645
9.8 CRITICAL

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate …

Sep 8, 2026
CVE-2026-58113
6.1 MEDIUM

A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter …

Sep 8, 2026
CVE-2026-50093
9.0 CRITICAL

A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 …

Sep 8, 2026
CVE-2026-34223
8.2 HIGH

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All …

Sep 8, 2026
CVE-2026-84820
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

Sep 8, 2026
CVE-2026-84818
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

Sep 8, 2026
CVE-2026-84817
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

Sep 8, 2026
CVE-2026-81806
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from …

Sep 8, 2026
CVE-2026-81802
6.5 MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

Sep 8, 2026
CVE-2026-81798
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through …

Sep 8, 2026
CVE-2026-81792
6.5 MEDIUM

Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.

Sep 8, 2026
CVE-2026-81790
7.5 HIGH

Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási …

Sep 8, 2026
CVE-2026-81781
7.1 HIGH

Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a …

Sep 8, 2026
CVE-2026-76561
7.2 HIGH

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile …

Sep 8, 2026
CVE-2026-71375
7.4 HIGH

Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before …

Sep 8, 2026
CVE-2026-71374
9.8 CRITICAL

Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 …

Sep 8, 2026
CVE-2026-48888
7.5 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

Sep 8, 2026
CVE-2026-86519
5.3 MEDIUM

A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. …

Sep 8, 2026
CVE-2026-86518
6.3 MEDIUM

A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument …

Sep 8, 2026
CVE-2026-86517
6.3 MEDIUM

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a …

Sep 8, 2026
CVE-2026-86516
4.7 MEDIUM

A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC …

Sep 8, 2026
CVE-2026-86515
4.3 MEDIUM

A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such …

Sep 8, 2026
CVE-2026-86514
6.3 MEDIUM

A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This …

Sep 8, 2026
CVE-2026-86513
5.3 MEDIUM

A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer …

Sep 8, 2026
CVE-2026-86512
6.3 MEDIUM

A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. …

Sep 8, 2026
CVE-2026-86511
5.3 MEDIUM

A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in …

Sep 8, 2026
CVE-2026-75811

Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware …

Sep 8, 2026
CVE-2026-75810

Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending …

Sep 8, 2026
CVE-2026-75809

Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication …

Sep 8, 2026
CVE-2026-75808

Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by …

Sep 8, 2026
CVE-2026-19397

Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection …

Sep 8, 2026
CVE-2026-18023

Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via …

Sep 8, 2026
CVE-2026-16006

Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a …

Sep 8, 2026
CVE-2026-16005

Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing …

Sep 8, 2026
CVE-2026-16004

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL …

Sep 8, 2026
CVE-2026-16003

Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via …

Sep 8, 2026
CVE-2026-12962

A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the …

Sep 8, 2026
CVE-2026-86510
9.9 CRITICAL

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to …

Sep 8, 2026
CVE-2026-86509
9.6 CRITICAL

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes …

Sep 8, 2026
CVE-2026-82710

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output …

Sep 8, 2026
CVE-2026-76977
4.3 MEDIUM

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing …

Sep 8, 2026
CVE-2026-76971
6.5 MEDIUM

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. …

Sep 8, 2026
CVE-2026-76969
9.4 CRITICAL

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially …

Sep 8, 2026
CVE-2026-76968
6.5 MEDIUM

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensitive …

Sep 8, 2026
CVE-2026-76967
7.8 HIGH

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the …

Sep 8, 2026
CVE-2026-76963
4.3 MEDIUM

Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive …

Sep 8, 2026
CVE-2026-76962
4.3 MEDIUM

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.