CVE Database

4627+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-42040
3.7 LOW

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in lib/helpers/AxiosURLSearchParams.js contains a character …

Apr 24, 2026
CVE-2026-41321
2.2 LOW

@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote images in packages/integrations/cloudflare/src/utils/image-binding-transform.ts uses the default …

Apr 24, 2026
CVE-2026-31051
3.8 LOW

An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to cause a denial of service via the Client Balance component

Apr 24, 2026
CVE-2026-41357
3.3 LOW

OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can exploit this by …

Apr 23, 2026
CVE-2026-41354
3.7 LOW

OpenClaw before 2026.4.2 contains an insufficient scope vulnerability in Zalo webhook replay dedupe keys that allows legitimate events from different conversations or senders to collide. …

Apr 23, 2026
CVE-2026-41333
3.7 LOW

OpenClaw before 2026.3.31 contains an authentication rate limiting bypass vulnerability that allows attackers to circumvent shared authentication protections using fake device tokens. Attackers can exploit …

Apr 23, 2026
CVE-2026-2708
3.7 LOW

A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate …

Apr 23, 2026
CVE-2026-4512
3.5 LOW

The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key setting before outputting it in a JavaScript string context …

Apr 23, 2026
CVE-2026-41988
3.2 LOW

uuid before 14.0.0 can make unexpected writes when external output buffers are used, and the UUID version is 3, 5, or 6. In particular, UUID …

Apr 23, 2026
CVE-2026-1272
2.7 LOW

IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user access control panel.

Apr 23, 2026
CVE-2026-34067
3.1 LOW

nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` panics on a malformed proof where `history.len() != …

Apr 22, 2026
CVE-2026-3254
3.5 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user …

Apr 22, 2026
CVE-2026-35381
3.3 LOW

A logic error in the cut utility of uutils coreutils causes the utility to ignore the -s (only-delimited) flag when using the -z (null-terminated) and …

Apr 22, 2026
CVE-2026-35379
3.3 LOW

A logic error in the tr utility of uutils coreutils causes the program to incorrectly define the [:graph:] and [:print:] character classes. The implementation mistakenly …

Apr 22, 2026
CVE-2026-35378
3.3 LOW

A logic error in the expr utility of uutils coreutils causes the program to evaluate parenthesized subexpressions during the parsing phase rather than at the …

Apr 22, 2026
CVE-2026-35377
3.3 LOW

A logic error in the env utility of uutils coreutils causes a failure to correctly parse command-line arguments when utilizing the -S (split-string) option. In …

Apr 22, 2026
CVE-2026-35375
3.3 LOW

A logic error in the split utility of uutils coreutils causes the corruption of output filenames when provided with non-UTF-8 prefix or suffix inputs. The …

Apr 22, 2026
CVE-2026-35373
3.3 LOW

A logic error in the ln utility of uutils coreutils causes the program to reject source paths containing non-UTF-8 filename bytes when using target-directory forms …

Apr 22, 2026
CVE-2026-35371
3.3 LOW

The id utility in uutils coreutils exhibits incorrect behavior in its "pretty print" output when the real UID and effective UID differ. The implementation incorrectly …

Apr 22, 2026
CVE-2026-35367
3.3 LOW

The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted permissions. This causes the file to inherit umask-based permissions, …

Apr 22, 2026
CVE-2026-35362
3.6 LOW

The safe_traversal module in uutils coreutils, which provides protection against Time-of-Check to Time-of-Use (TOCTOU) symlink races using file-descriptor-relative syscalls, is incorrectly limited to Linux targets. …

Apr 22, 2026
CVE-2026-35361
3.4 LOW

The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the …

Apr 22, 2026
CVE-2026-35353
3.3 LOW

The mkdir utility in uutils coreutils incorrectly applies permissions when using the -m flag by creating a directory with umask-derived permissions (typically 0755) before subsequently …

Apr 22, 2026
CVE-2026-35346
3.3 LOW

The comm utility in uutils coreutils silently corrupts data by performing lossy UTF-8 conversion on all output lines. The implementation uses String::from_utf8_lossy(), which replaces invalid …

Apr 22, 2026
CVE-2026-35344
3.3 LOW

The dd utility in uutils coreutils suppresses errors during file truncation operations by unconditionally calling Result::ok() on truncation attempts. While intended to mimic GNU behavior …

Apr 22, 2026
CVE-2026-35343
3.3 LOW

The cut utility in uutils coreutils incorrectly handles the -s (only-delimited) option when a newline character is specified as the delimiter. The implementation fails to …

Apr 22, 2026
CVE-2026-35342
3.3 LOW

The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR …

Apr 22, 2026
CVE-2025-9957
2.7 LOW

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain …

Apr 22, 2026
CVE-2026-33599
3.1 LOW

A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to …

Apr 22, 2026
CVE-2026-33597
3.7 LOW

PRSD detection denial of service

Apr 22, 2026
CVE-2026-33596
3.1 LOW

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of …

Apr 22, 2026
CVE-2026-6842
2.5 LOW

A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directory permissions (0777 instead of 0700) for …

Apr 22, 2026
CVE-2026-22746
3.7 LOW

Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's …

Apr 22, 2026
CVE-2026-6416
2.7 LOW

Tanium addressed an uncontrolled resource consumption vulnerability in Interact.

Apr 22, 2026
CVE-2026-6408
2.7 LOW

Tanium addressed an information disclosure vulnerability in Tanium Server.

Apr 22, 2026
CVE-2026-6392
2.7 LOW

Tanium addressed an information disclosure vulnerability in Threat Response.

Apr 22, 2026
CVE-2026-3307
2.7 LOW

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning …

Apr 21, 2026
CVE-2026-6830
3.3 LOW

nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next …

Apr 21, 2026
CVE-2026-35250
2.3 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high …

Apr 21, 2026
CVE-2026-35249
3.2 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high …

Apr 21, 2026
CVE-2026-34312
2.4 LOW

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row …

Apr 21, 2026
CVE-2026-34268
2.9 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are …

Apr 21, 2026
CVE-2026-22018
3.7 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are …

Apr 21, 2026
CVE-2026-22014
3.8 LOW

Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Workflow and Business Events). Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable …

Apr 21, 2026
CVE-2026-22008
3.7 LOW

Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker …

Apr 21, 2026
CVE-2026-22007
2.9 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are …

Apr 21, 2026
CVE-2026-22001
2.7 LOW

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable …

Apr 21, 2026
CVE-2026-6745
3.5 LOW

A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation …

Apr 21, 2026
CVE-2026-6743
3.5 LOW

A vulnerability has been found in WebSystems WebTOTUM 2026. This impacts an unknown function of the component Calendar. The manipulation leads to cross site scripting. …

Apr 21, 2026
CVE-2026-40279
3.7 LOW

BACnet Stack is a BACnet open source protocol stack C library for embedded systems. Prior to 1.4.3, decode_signed32() in src/bacnet/bacint.c reconstructs a 32-bit signed integer …

Apr 21, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.