CVE Database

130945+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76871
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in mod_vpn_remote/plan.json, pptpd_user_show.cgi, pptp_client_config_show.cgi, and l2tpd_user_show.cgi. Attackers can leverage these components to obtain PPTP and …

Sep 15, 2026
CVE-2026-76870
7.1 HIGH

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation routine triggered by short firmware uploads. Attackers can upload a truncated …

Sep 15, 2026
CVE-2026-76869
7.2 HIGH

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper sscanf token parsing. Attackers can exploit this flaw by submitting crafted …

Sep 15, 2026
CVE-2026-76868
4.9 MEDIUM

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in route_policy_add.cgi caused by a missing exit_port parameter. Attackers can send requests lacking the exit_port …

Sep 15, 2026
CVE-2026-76867
5.4 MEDIUM

Netcore NR255-V firmware version 1.5.130703 contains a stored cross-site scripting vulnerability in routing and NAT configuration CGI components including routing_tab_add_cgi, routing_table_list_show_cgi, route_policy_add_cgi, and route_policy_parame_show_cgi. Attackers …

Sep 15, 2026
CVE-2026-76866
7.2 HIGH

Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNSset_cgi.c and related ddns_Proc.c components, enabling os command argument injection. …

Sep 15, 2026
CVE-2026-76865
4.9 MEDIUM

Netcore NR255-V version 1.5.130703 contains a null pointer dereference vulnerability in the QoS setter CGI handlers filter_conn_del_cgi.c and gre_prio_set_cgi.c due to unchecked atoi() results. An …

Sep 15, 2026
CVE-2026-76864
4.8 MEDIUM

NR255-V version 1.5.130703 fails to sanitize QoS rule names before they are parsed via eval() in qos_xianz_add_cgi, qos_xianz_show_cgi, qos_filter_add_cgi, and qos_filter_show_cgi handlers. An attacker can …

Sep 15, 2026
CVE-2026-76863
4.3 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the mod_qos_bandwidth plan.json handling within filter_conns_dump_cgi.c and IGD_CgiCall.c. Authenticated users with broad roles can …

Sep 15, 2026
CVE-2026-76862
8.8 HIGH

Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launch paths, including ntools_start_set_cgi, ntools_tcpdump_start_set_cgi, exe_default, and ntools_proc components. Attackers …

Sep 15, 2026
CVE-2026-76861
8.8 HIGH

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit …

Sep 15, 2026
CVE-2026-76860
8.8 HIGH

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC …

Sep 15, 2026
CVE-2026-76859
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the user_pass_show.cgi component. Low-privilege attackers can exploit this flaw via ui_config_2.xml and misc.js to …

Sep 15, 2026
CVE-2026-76858
4.8 MEDIUM

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in ddns_wan_list_show.cgi caused by unsafe eval() handling of DDNS data. Attackers can inject malicious script …

Sep 15, 2026
CVE-2026-76857
6.5 MEDIUM

Netcore NR255-V firmware version 1.5.130703 contains a sensitive information disclosure vulnerability in the ddns_wan_list_show.cgi endpoint and related DDNSset_cgi, IGD_GetCgiHandler, and IGD_CgiCall components. Attackers who reach …

Sep 15, 2026
CVE-2026-76856
8.1 HIGH

Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config_set_cgi, wan_num_set_cgi, and lan_ip_change_cgi endpoints. Attackers can craft forged requests to trick …

Sep 15, 2026
CVE-2026-76855
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in the audit endpoints handled by l7_web_auth_log_dump_cgi.c, audit_get_cgi.c, and mod_dispatch_auth/plan.json. Attackers can query these audit …

Sep 15, 2026
CVE-2026-76854
6.5 MEDIUM

Netcore NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l7_web_auth_user_show.cgi related to captive-portal credential handling. Attackers can query this component to obtain captive-portal …

Sep 15, 2026
CVE-2026-76853
8.1 HIGH

Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi restore archive prefix validation. Attackers can exploit the flawed prefix check …

Sep 15, 2026
CVE-2026-76852
8.8 HIGH

Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to …

Sep 15, 2026
CVE-2026-73807
9.8 CRITICAL

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could …

Sep 15, 2026
CVE-2026-73444
4.7 MEDIUM

On affected platforms running Arista EOS with VRRPv2 IP Authentication Header (IP-AH) authentication configured, an unauthenticated attacker with access to the layer 2 network segment …

Sep 15, 2026
CVE-2026-73437
9.6 CRITICAL

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP …

Sep 15, 2026
CVE-2026-61560
9.8 CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. …

Sep 15, 2026
CVE-2026-10150

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 15, 2026
CVE-2026-10149

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 15, 2026
CVE-2026-10145

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 15, 2026
CVE-2026-10144
7.8 HIGH

Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands by supplying a crafted URL containing shell metacharacters to …

Sep 15, 2026
CVE-2026-92237
6.5 MEDIUM

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with …

Sep 15, 2026
CVE-2026-92234
5.4 MEDIUM

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who …

Sep 15, 2026
CVE-2026-92000
7.5 HIGH

adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncompressed size. Attackers can craft malicious ZIP archives …

Sep 15, 2026
CVE-2026-91939
9.8 CRITICAL

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. …

Sep 15, 2026
CVE-2026-91749
9.6 CRITICAL

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 15, 2026
CVE-2026-91748
8.3 HIGH

Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 15, 2026
CVE-2026-91747
3.1 LOW

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data …

Sep 15, 2026
CVE-2026-91746
4.3 MEDIUM

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 15, 2026
CVE-2026-91745
8.8 HIGH

Use after free in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91744
5.3 MEDIUM

Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged …

Sep 15, 2026
CVE-2026-91743
8.3 HIGH

Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Sep 15, 2026
CVE-2026-91742

Confused deputy in PriceTracking in Google Chrome on on iOS prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to bypass system access restrictions …

Sep 15, 2026
CVE-2026-91741
8.8 HIGH

Type confusion in CacheStorage in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 15, 2026
CVE-2026-91740
4.3 MEDIUM

Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security …

Sep 15, 2026
CVE-2026-91739
4.2 MEDIUM

Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements …

Sep 15, 2026
CVE-2026-91738
9.6 CRITICAL

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 15, 2026
CVE-2026-91737
8.8 HIGH

Use after free in PDF in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91736
8.8 HIGH

Use after free in DOM in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91735
8.3 HIGH

Incorrect authorization in WebUI in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code …

Sep 15, 2026
CVE-2026-91734
7.4 HIGH

Incorrect authorization in Core in Google Chrome on on Windows prior to 153.0.8010.47 allowed a local attacker to execute arbitrary code outside the sandbox via …

Sep 15, 2026
CVE-2026-91733
8.3 HIGH

Improper state validation in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to read memory outside …

Sep 15, 2026
CVE-2026-91732

Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.