CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-86281
4.3 MEDIUM

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in …

Sep 7, 2026
CVE-2026-86280
5.3 MEDIUM

A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads …

Sep 7, 2026
CVE-2026-84256

An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a …

Sep 7, 2026
CVE-2026-84226

OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

Sep 7, 2026
CVE-2026-82312

OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on …

Sep 7, 2026
CVE-2026-81830

The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation

Sep 7, 2026
CVE-2026-81738

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

Sep 7, 2026
CVE-2026-78254
7.4 HIGH

The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it …

Sep 7, 2026
CVE-2026-78221

An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose …

Sep 7, 2026
CVE-2026-78043

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files …

Sep 7, 2026
CVE-2026-14296
7.5 HIGH

When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional …

Sep 7, 2026
CVE-2026-86279
6.3 MEDIUM

A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of …

Sep 7, 2026
CVE-2026-86278
4.3 MEDIUM

A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The …

Sep 7, 2026
CVE-2026-86277
7.3 HIGH

A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation …

Sep 7, 2026
CVE-2026-79698
9.9 CRITICAL

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the …

Sep 7, 2026
CVE-2026-79697
9.9 CRITICAL

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function …

Sep 7, 2026
CVE-2026-86276
7.3 HIGH

A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing …

Sep 7, 2026
CVE-2026-86275
5.3 MEDIUM

A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a …

Sep 7, 2026
CVE-2026-86274
5.3 MEDIUM

A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication …

Sep 7, 2026
CVE-2026-86273
7.3 HIGH

A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the …

Sep 7, 2026
CVE-2026-86272
7.3 HIGH

A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation …

Sep 7, 2026
CVE-2026-86271
4.7 MEDIUM

A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing a manipulation results in missing authorization. …

Sep 7, 2026
CVE-2026-86270
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation …

Sep 7, 2026
CVE-2026-86315
6.2 MEDIUM

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt …

Sep 7, 2026
CVE-2026-86269
6.3 MEDIUM

A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation …

Sep 7, 2026
CVE-2026-86268
7.3 HIGH

A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email …

Sep 7, 2026
CVE-2026-86267
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The …

Sep 7, 2026
CVE-2026-86265
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such …

Sep 7, 2026
CVE-2026-86314
6.2 MEDIUM

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read …

Sep 7, 2026
CVE-2026-86313
7.8 HIGH

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

Sep 7, 2026
CVE-2026-86264
4.3 MEDIUM

A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endpoint. …

Sep 7, 2026
CVE-2026-86263
7.3 HIGH

A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The …

Sep 7, 2026
CVE-2026-86262
7.3 HIGH

A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order …

Sep 7, 2026
CVE-2026-86261
7.3 HIGH

A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component …

Sep 7, 2026
CVE-2026-86260
6.5 MEDIUM

A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the …

Sep 7, 2026
CVE-2026-86245
6.3 MEDIUM

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a …

Sep 7, 2026
CVE-2026-86244
4.3 MEDIUM

A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. …

Sep 7, 2026
CVE-2026-86241
4.3 MEDIUM

A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. …

Sep 7, 2026
CVE-2026-86240
4.7 MEDIUM

A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. …

Sep 7, 2026
CVE-2026-86239
5.3 MEDIUM

A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor …

Sep 7, 2026
CVE-2026-20518
4.4 MEDIUM

In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor …

Sep 7, 2026
CVE-2026-20517
6.7 MEDIUM

In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious …

Sep 7, 2026
CVE-2026-20516
5.5 MEDIUM

In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution …

Sep 7, 2026
CVE-2026-20515
5.5 MEDIUM

In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. …

Sep 7, 2026
CVE-2026-20514
4.4 MEDIUM

In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious …

Sep 7, 2026
CVE-2026-20513
4.4 MEDIUM

In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor …

Sep 7, 2026
CVE-2026-20512
6.7 MEDIUM

In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a …

Sep 7, 2026
CVE-2026-20511
6.7 MEDIUM

In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor …

Sep 7, 2026
CVE-2026-20510
6.7 MEDIUM

In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious …

Sep 7, 2026
CVE-2026-20509
6.7 MEDIUM

In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege …

Sep 7, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.