CVE Database

5195+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-90824
3.3 LOW

A vulnerability has been found in GPAC 26.07.0. Affected is the function gf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the component MP4Box. The manipulation leads to …

Sep 14, 2026
CVE-2026-19086
3.3 LOW

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An …

Sep 14, 2026
CVE-2026-16190
3.1 LOW

IBM WebSphere Application Server 9.0, and 8.5 is affected by an authorization bypass vulnerability.

Sep 14, 2026
CVE-2026-90811
3.3 LOW

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission …

Sep 14, 2026
CVE-2026-57583
3.3 LOW

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar …

Sep 14, 2026
CVE-2026-55866
3.7 LOW

SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION …

Sep 14, 2026
CVE-2026-49400
3.3 LOW

October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state …

Sep 14, 2026
CVE-2026-46696
3.3 LOW

October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security …

Sep 14, 2026
CVE-2026-44162
2.7 LOW

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of …

Sep 14, 2026
CVE-2026-54542
3.7 LOW

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash …

Sep 14, 2026
CVE-2026-54541
3.7 LOW

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash …

Sep 14, 2026
CVE-2026-90713
3.3 LOW

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the …

Sep 14, 2026
CVE-2026-90696
3.5 LOW

A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component …

Sep 14, 2026
CVE-2026-90695
3.5 LOW

A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component …

Sep 14, 2026
CVE-2026-90694
3.5 LOW

A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management …

Sep 14, 2026
CVE-2026-25832
3.7 LOW

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

Sep 14, 2026
CVE-2025-26790
3.7 LOW

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by …

Sep 14, 2026
CVE-2026-90685
2.8 LOW

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component …

Sep 14, 2026
CVE-2023-37366
2.8 LOW

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, …

Sep 14, 2026
CVE-2023-37253
3.1 LOW

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

Sep 14, 2026
CVE-2026-90684
2.8 LOW

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component …

Sep 14, 2026
CVE-2026-90683
3.3 LOW

A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation …

Sep 14, 2026
CVE-2026-90681
3.3 LOW

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. …

Sep 14, 2026
CVE-2023-37252
3.1 LOW

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.

Sep 14, 2026
CVE-2023-32778
3.3 LOW

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.

Sep 14, 2026
CVE-2023-24291
2.9 LOW

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

Sep 14, 2026
CVE-2023-24288
2.9 LOW

An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.

Sep 14, 2026
CVE-2023-24287
2.9 LOW

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

Sep 14, 2026
CVE-2023-24286
2.9 LOW

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

Sep 14, 2026
CVE-2023-24285
2.9 LOW

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.

Sep 14, 2026
CVE-2023-24284
2.9 LOW

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.

Sep 14, 2026
CVE-2026-90623
3.7 LOW

A weakness has been identified in andreashappe cochise up to 0.4.1. Affected is the function asyncssh.connect of the file src/cochise/ssh_connection.py of the component SSH Host …

Sep 14, 2026
CVE-2026-90622
3.3 LOW

A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing …

Sep 14, 2026
CVE-2023-24283
2.9 LOW

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted …

Sep 14, 2026
CVE-2023-24035
3.5 LOW

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to …

Sep 14, 2026
CVE-2023-24034
3.1 LOW

An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a …

Sep 14, 2026
CVE-2023-22632
2.7 LOW

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.

Sep 14, 2026
CVE-2023-22631
2.7 LOW

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.

Sep 14, 2026
CVE-2026-38924
2.9 LOW

In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 was …

Sep 14, 2026
CVE-2026-33970
3.5 LOW

An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, …

Sep 14, 2026
CVE-2026-33968
2.8 LOW

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a …

Sep 14, 2026
CVE-2026-33967
2.8 LOW

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an …

Sep 14, 2026
CVE-2026-33966
2.8 LOW

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in …

Sep 14, 2026
CVE-2026-90613
3.3 LOW

A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the …

Sep 14, 2026
CVE-2026-90612
3.3 LOW

A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads …

Sep 14, 2026
CVE-2026-90611
3.3 LOW

A vulnerability was determined in GPAC up to f1219cde. This impacts the function xmt_parse_element of the file scene_manager/loader_xmt.c of the component MP4Box. Executing a manipulation …

Sep 14, 2026
CVE-2026-90610
3.3 LOW

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation …

Sep 14, 2026
CVE-2026-33962
2.8 LOW

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can …

Sep 14, 2026
CVE-2026-33960
2.8 LOW

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl …

Sep 14, 2026
CVE-2026-33956
2.8 LOW

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg …

Sep 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.