CVE Database

11693+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-89930
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Service local TLB flushes on failed nested VM-Enter KVM services local TLB flushes …

Sep 16, 2026
CVE-2026-89918
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly handle end of VA space TLBI invalidation Our TLB invalidation by VA …

Sep 16, 2026
CVE-2026-89916
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make VNCR invalidation participate in MMU invalidation retry A VNCR TLB invalidation can …

Sep 16, 2026
CVE-2026-89915
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Remove VM-wide VNCR mapping counter The global VNCR mapping counter is used to …

Sep 16, 2026
CVE-2026-89914
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Sign-extend VA for range-based TLBI invalidation When the decode_range_tlbi() helper was moved to …

Sep 16, 2026
CVE-2026-89857
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Hold qpair lock when sending NVMe LS reject qla_nvme_ls_reject_iocb() allocates from and advances …

Sep 16, 2026
CVE-2026-89847
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Avoid double completion in async IOCB timeout qla2x00_async_iocb_timeout() tries to abort a timed-out …

Sep 16, 2026
CVE-2026-89846
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Bound rsp_info_len to avoid OOB sense-data read In qla2x00_status_entry(), the FWI2 status path …

Sep 16, 2026
CVE-2026-86106
9.6 CRITICAL

An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command …

Sep 16, 2026
CVE-2026-73453
10.0 CRITICAL

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with …

Sep 16, 2026
CVE-2026-89788
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix tree connection use-after-free in smb2_tree_connect() ksmbd_tree_conn_connect() publishes a new tree connection in sess->tree_conns …

Sep 16, 2026
CVE-2026-89786
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bounds read in ext4_read_inline_dir() ext4_read_inline_dir() can read a dirent header past the end …

Sep 16, 2026
CVE-2026-89783
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: xfrm6: fix out-of-bounds write in xfrm6_input_addr() when secpath is full The depth check in xfrm6_input_addr() …

Sep 16, 2026
CVE-2026-89779
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: validate ef->size covers the record's name and value When an EA record has a …

Sep 16, 2026
CVE-2026-89778
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: isofs: fix out-of-bounds page array access on empty zisofs block zisofs_uncompress_block()'s empty-block fast path returns …

Sep 16, 2026
CVE-2026-89775
9.3 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects …

Sep 16, 2026
CVE-2026-27565
9.8 CRITICAL

An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active …

Sep 16, 2026
CVE-2026-27546
9.8 CRITICAL

An unauthenticated remote attacker can exploit an authentication bypass in the _account_log function to log in as an admin, even when accounts are properly configured.

Sep 16, 2026
CVE-2026-73447
9.1 CRITICAL

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC …

Sep 16, 2026
CVE-2026-14349
9.8 CRITICAL

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This …

Sep 16, 2026
CVE-2026-12793
9.8 CRITICAL

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is …

Sep 16, 2026
CVE-2026-81855
9.1 CRITICAL

A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.

Sep 15, 2026
CVE-2026-78225
9.0 CRITICAL

A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

Sep 15, 2026
CVE-2026-73807
9.8 CRITICAL

The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could …

Sep 15, 2026
CVE-2026-73437
9.6 CRITICAL

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP …

Sep 15, 2026
CVE-2026-61560
9.8 CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. …

Sep 15, 2026
CVE-2026-91939
9.8 CRITICAL

Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. …

Sep 15, 2026
CVE-2026-91749
9.6 CRITICAL

Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 15, 2026
CVE-2026-91738
9.6 CRITICAL

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a …

Sep 15, 2026
CVE-2026-91729
9.6 CRITICAL

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox …

Sep 15, 2026
CVE-2026-91728
9.6 CRITICAL

Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML …

Sep 15, 2026
CVE-2026-91718
9.6 CRITICAL

Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91716
9.6 CRITICAL

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-91710
9.6 CRITICAL

Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted …

Sep 15, 2026
CVE-2026-66890
9.6 CRITICAL

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

Sep 15, 2026
CVE-2026-66887
9.6 CRITICAL

The affected products are missing authorization on state-changing CGIs and session checks are not performed.

Sep 15, 2026
CVE-2026-61568
9.6 CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin …

Sep 15, 2026
CVE-2026-61559
9.6 CRITICAL

`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, …

Sep 15, 2026
CVE-2026-54337
9.8 CRITICAL

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system …

Sep 15, 2026
CVE-2026-89040
9.8 CRITICAL

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on …

Sep 15, 2026
CVE-2026-87230
10.0 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87223
9.1 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87217
9.1 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87214
9.1 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87189
9.1 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87188
9.8 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87186
9.6 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87184
9.8 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87176
9.1 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026
CVE-2026-87175
9.1 CRITICAL

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows …

Sep 15, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.