CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-20508
6.7 MEDIUM

In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious …

Sep 7, 2026
CVE-2026-20507
6.7 MEDIUM

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a …

Sep 7, 2026
CVE-2026-20506
6.7 MEDIUM

In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a …

Sep 7, 2026
CVE-2026-20504
5.3 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Sep 7, 2026
CVE-2026-20503
5.3 MEDIUM

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE …

Sep 7, 2026
CVE-2026-20502
8.4 HIGH

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 7, 2026
CVE-2026-20501
8.4 HIGH

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with …

Sep 7, 2026
CVE-2026-20500
5.5 MEDIUM

In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges …

Sep 7, 2026
CVE-2026-16876

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with …

Sep 7, 2026
CVE-2026-86238
4.3 MEDIUM

A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback …

Sep 7, 2026
CVE-2026-86237
5.3 MEDIUM

A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argument …

Sep 7, 2026
CVE-2026-86236
6.3 MEDIUM

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of …

Sep 7, 2026
CVE-2026-86235
6.3 MEDIUM

A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the …

Sep 7, 2026
CVE-2026-86234
6.3 MEDIUM

A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument …

Sep 7, 2026
CVE-2026-86233
6.3 MEDIUM

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. …

Sep 7, 2026
CVE-2026-86304
9.8 CRITICAL

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no …

Sep 6, 2026
CVE-2026-86232
6.3 MEDIUM

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing …

Sep 6, 2026
CVE-2026-86231
3.7 LOW

A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86228
4.3 MEDIUM

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the …

Sep 6, 2026
CVE-2026-86227
3.1 LOW

A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument …

Sep 6, 2026
CVE-2026-86226
3.5 LOW

A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The …

Sep 6, 2026
CVE-2026-86225
7.3 HIGH

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The …

Sep 6, 2026
CVE-2026-86224
7.3 HIGH

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of …

Sep 6, 2026
CVE-2026-86223
7.3 HIGH

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of …

Sep 6, 2026
CVE-2026-86222
7.3 HIGH

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of …

Sep 6, 2026
CVE-2026-86221
7.3 HIGH

A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This …

Sep 6, 2026
CVE-2026-86220
7.3 HIGH

A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation …

Sep 6, 2026
CVE-2026-86219
9.8 CRITICAL

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the …

Sep 6, 2026
CVE-2026-82209
8.2 HIGH

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly …

Sep 6, 2026
CVE-2026-82208
7.5 HIGH

With the wolfSSL backend, when CA caching is enabled and an `CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can silently reinstall the cached store after …

Sep 6, 2026
CVE-2026-80255
7.5 HIGH

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store …

Sep 6, 2026
CVE-2026-80231
7.5 HIGH

A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA Store …

Sep 6, 2026
CVE-2026-80230
7.5 HIGH

When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and `CURLOPT_SSL_VERIFYHOST = 0`), libcurl fails to enforce public key pinning …

Sep 6, 2026
CVE-2026-80229
7.5 HIGH

When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated …

Sep 6, 2026
CVE-2026-19931
9.8 CRITICAL

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done …

Sep 6, 2026
CVE-2026-18924
9.1 CRITICAL

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to …

Sep 6, 2026
CVE-2026-13608
7.4 HIGH

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker …

Sep 6, 2026
CVE-2026-82751

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by …

Sep 6, 2026
CVE-2026-82750

Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by …

Sep 6, 2026
CVE-2026-83534
6.4 MEDIUM

PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue …

Sep 6, 2026
CVE-2026-19634
6.4 MEDIUM

PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If …

Sep 6, 2026
CVE-2026-19633
8.8 HIGH

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted …

Sep 6, 2026
CVE-2026-86283

MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control list (ACL). The CollectionsController::view() …

Sep 6, 2026
CVE-2026-86217
5.3 MEDIUM

A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component …

Sep 6, 2026
CVE-2026-86216
4.3 MEDIUM

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The …

Sep 6, 2026
CVE-2026-86215
4.3 MEDIUM

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation …

Sep 6, 2026
CVE-2026-86259
7.5 HIGH

OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider …

Sep 6, 2026
CVE-2026-86258
5.9 MEDIUM

nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling …

Sep 6, 2026
CVE-2026-86214
7.3 HIGH

A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. …

Sep 6, 2026
CVE-2026-86213
7.3 HIGH

A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. The manipulation of …

Sep 6, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.