CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-23788
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due …

Sep 14, 2026
CVE-2026-23787
4.2 MEDIUM

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the …

Sep 14, 2026
CVE-2025-68624
4.3 MEDIUM

N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses …

Sep 14, 2026
CVE-2025-63842
5.4 MEDIUM

A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript …

Sep 14, 2026
CVE-2024-53922
5.7 MEDIUM

An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check …

Sep 14, 2026
CVE-2022-42917
6.7 MEDIUM

In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config …

Sep 14, 2026
CVE-2026-90600
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the …

Sep 13, 2026
CVE-2026-15892
5.3 MEDIUM

The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for read, a data buffer) via k_malloc() when …

Sep 13, 2026
CVE-2026-90599
4.3 MEDIUM

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead …

Sep 13, 2026
CVE-2026-90598
6.3 MEDIUM

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of …

Sep 13, 2026
CVE-2026-90597
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such …

Sep 13, 2026
CVE-2026-90596
6.5 MEDIUM

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer …

Sep 13, 2026
CVE-2026-90595
6.3 MEDIUM

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing …

Sep 13, 2026
CVE-2026-90594
6.3 MEDIUM

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation …

Sep 13, 2026
CVE-2026-90584
5.3 MEDIUM

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component …

Sep 13, 2026
CVE-2026-89050
4.3 MEDIUM

The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the configured payment gateway before marking an ad-selling …

Sep 13, 2026
CVE-2026-36989
5.8 MEDIUM

A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.

Sep 13, 2026
CVE-2026-90583
4.3 MEDIUM

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the …

Sep 13, 2026
CVE-2026-90582
5.3 MEDIUM

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation …

Sep 13, 2026
CVE-2026-90581
6.3 MEDIUM

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument …

Sep 13, 2026
CVE-2026-90580
6.3 MEDIUM

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. …

Sep 13, 2026
CVE-2026-29812
4.3 MEDIUM

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

Sep 13, 2026
CVE-2026-29810
4.3 MEDIUM

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

Sep 13, 2026
CVE-2026-90578
5.3 MEDIUM

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component …

Sep 13, 2026
CVE-2026-90577
5.3 MEDIUM

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. …

Sep 13, 2026
CVE-2025-70819
6.3 MEDIUM

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

Sep 13, 2026
CVE-2020-15875
5.0 MEDIUM

An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a …

Sep 13, 2026
CVE-2026-90574
6.3 MEDIUM

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of …

Sep 13, 2026
CVE-2026-90572
4.7 MEDIUM

A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of …

Sep 13, 2026
CVE-2026-90571
4.3 MEDIUM

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing …

Sep 13, 2026
CVE-2026-90565
5.3 MEDIUM

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of …

Sep 13, 2026
CVE-2026-90527
4.3 MEDIUM

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. …

Sep 13, 2026
CVE-2026-90525
6.3 MEDIUM

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of …

Sep 13, 2026
CVE-2026-90782
5.3 MEDIUM

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers …

Sep 13, 2026
CVE-2026-90781
4.4 MEDIUM

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field …

Sep 13, 2026
CVE-2026-90521
6.3 MEDIUM

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The …

Sep 13, 2026
CVE-2026-90520
6.3 MEDIUM

A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. …

Sep 13, 2026
CVE-2026-90519
6.3 MEDIUM

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the …

Sep 13, 2026
CVE-2026-90775
6.5 MEDIUM

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious …

Sep 13, 2026
CVE-2026-90518
6.3 MEDIUM

A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of …

Sep 13, 2026
CVE-2026-90517
5.3 MEDIUM

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument …

Sep 13, 2026
CVE-2026-90767
6.5 MEDIUM

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers …

Sep 13, 2026
CVE-2026-90513
6.5 MEDIUM

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API …

Sep 13, 2026
CVE-2026-90511
6.3 MEDIUM

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The …

Sep 13, 2026
CVE-2026-90507
6.3 MEDIUM

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such …

Sep 13, 2026
CVE-2026-90506
5.0 MEDIUM

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race …

Sep 13, 2026
CVE-2026-90505
5.0 MEDIUM

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be …

Sep 13, 2026
CVE-2026-90501
6.3 MEDIUM

A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument …

Sep 13, 2026
CVE-2026-90500
6.3 MEDIUM

A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This …

Sep 13, 2026
CVE-2026-90499
5.4 MEDIUM

A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. …

Sep 13, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.