CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-82738

Improper Input Validation vulnerability in ash-project ash allows an attacker to persistently deny reads of a record by storing a non-version-7 UUID in an Ash.Type.UUIDv7 …

Sep 1, 2026
CVE-2026-82737

Integer Overflow or Wraparound vulnerability in ash-project ash lets an attacker corrupt a stored vector and crash later reads of it by submitting a vector …

Sep 1, 2026
CVE-2026-82736

Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates its length or match constraints. …

Sep 1, 2026
CVE-2026-82735

Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to force an expensive regular expression to run on input that a length constraint should …

Sep 1, 2026
CVE-2026-82734

Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-finite decimal value that bypasses numeric bounds constraints …

Sep 1, 2026
CVE-2026-19032
5.3 MEDIUM

jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new …

Sep 1, 2026
CVE-2026-82733

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response …

Sep 1, 2026
CVE-2026-82732

Improper Input Validation vulnerability in ash-project ash_typescript allows a remote attacker to submit argument values outside a declared allowlist or bound on typed-controller routes. AshTypescript.TypedController.RequestHandler …

Sep 1, 2026
CVE-2026-82731

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who controls a path-parameter value to redirect a generated client's request, …

Sep 1, 2026
CVE-2026-82730

Incorrect Authorization vulnerability in ash-project ash_typescript allows an unauthorized RPC caller to read attribute values that Ash field policies denied. When a field policy denies …

Sep 1, 2026
CVE-2026-77950

Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error …

Sep 1, 2026
CVE-2026-77856

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node …

Sep 1, 2026
CVE-2026-75865
9.8 CRITICAL

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file …

Sep 1, 2026
CVE-2026-74837

Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_typescript allows an unauthenticated attacker to exhaust the BEAM atom table and abort the node …

Sep 1, 2026
CVE-2026-67395
5.9 MEDIUM

A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal …

Sep 1, 2026
CVE-2026-67394

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and …

Sep 1, 2026
CVE-2026-65643

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

Sep 1, 2026
CVE-2026-48932
3.7 LOW

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while …

Sep 1, 2026
CVE-2026-18743
2.5 LOW

A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead …

Sep 1, 2026
CVE-2026-19820

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows …

Sep 1, 2026
CVE-2026-83524
9.9 CRITICAL

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the …

Aug 31, 2026
CVE-2026-82971
10.0 CRITICAL

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of …

Aug 31, 2026
CVE-2026-82957
7.3 HIGH

A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook …

Aug 31, 2026
CVE-2026-82954
9.9 CRITICAL

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation …

Aug 31, 2026
CVE-2026-82922
7.3 HIGH

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of …

Aug 31, 2026
CVE-2026-82921
7.3 HIGH

A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the …

Aug 31, 2026
CVE-2026-82882
8.8 HIGH

Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated …

Aug 31, 2026
CVE-2026-82398

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py …

Aug 31, 2026
CVE-2026-82397
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. …

Aug 31, 2026
CVE-2026-82396
5.4 MEDIUM

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and …

Aug 31, 2026
CVE-2026-82395

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its …

Aug 31, 2026
CVE-2026-82394

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do …

Aug 31, 2026
CVE-2026-82393
7.5 HIGH

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts …

Aug 31, 2026
CVE-2026-77353
4.6 MEDIUM

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their …

Aug 31, 2026
CVE-2026-77352
4.3 MEDIUM

Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make …

Aug 31, 2026
CVE-2026-77351
3.5 LOW

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private …

Aug 31, 2026
CVE-2026-77348
8.2 HIGH

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php …

Aug 31, 2026
CVE-2026-83596
8.8 HIGH

A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

Aug 31, 2026
CVE-2026-82919
7.3 HIGH

A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component …

Aug 31, 2026
CVE-2026-82914
7.3 HIGH

A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact …

Aug 31, 2026
CVE-2026-82909
4.3 MEDIUM

A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component …

Aug 31, 2026
CVE-2026-82908
8.8 HIGH

A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the …

Aug 31, 2026
CVE-2026-82906
3.7 LOW

A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File …

Aug 31, 2026
CVE-2026-82852
5.4 MEDIUM

Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.

Aug 31, 2026
CVE-2026-82392
7.1 HIGH

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name …

Aug 31, 2026
CVE-2026-82346

A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to …

Aug 31, 2026
CVE-2026-82229
7.1 HIGH

Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.

Aug 31, 2026
CVE-2026-82228
8.1 HIGH

Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

Aug 31, 2026
CVE-2026-82226
9.8 CRITICAL

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

Aug 31, 2026
CVE-2026-82225
7.4 HIGH

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

Aug 31, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.