CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-76439
5.3 MEDIUM

A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to …

Sep 16, 2026
CVE-2026-76438
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations …

Sep 16, 2026
CVE-2026-76434
4.9 MEDIUM

A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to …

Sep 16, 2026
CVE-2026-76433
5.3 MEDIUM

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on …

Sep 16, 2026
CVE-2026-76432
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary …

Sep 16, 2026
CVE-2026-76431
4.9 MEDIUM

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to …

Sep 16, 2026
CVE-2026-76428
4.9 MEDIUM

A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the …

Sep 16, 2026
CVE-2026-76427
4.9 MEDIUM

A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on …

Sep 16, 2026
CVE-2026-76426
4.9 MEDIUM

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the …

Sep 16, 2026
CVE-2026-20350
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This …

Sep 16, 2026
CVE-2026-20309
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting …

Sep 16, 2026
CVE-2026-20290
5.8 MEDIUM

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote …

Sep 16, 2026
CVE-2026-20287
6.5 MEDIUM

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) …

Sep 16, 2026
CVE-2026-20286
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration …

Sep 16, 2026
CVE-2026-20285
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote …

Sep 16, 2026
CVE-2026-20283
6.5 MEDIUM

A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating …

Sep 16, 2026
CVE-2026-20282
4.9 MEDIUM

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This …

Sep 16, 2026
CVE-2026-20248
6.8 MEDIUM

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software …

Sep 16, 2026
CVE-2026-20235
4.9 MEDIUM

A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. …

Sep 16, 2026
CVE-2026-20121
5.3 MEDIUM

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure …

Sep 16, 2026
CVE-2026-20120
5.8 MEDIUM

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure …

Sep 16, 2026
CVE-2026-20072
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are …

Sep 16, 2026
CVE-2026-92526
6.3 MEDIUM

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the …

Sep 16, 2026
CVE-2026-92475
5.3 MEDIUM

A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds …

Sep 16, 2026
CVE-2026-87116
6.5 MEDIUM

Tanium addressed a server-side request forgery vulnerability in Threat Response.

Sep 16, 2026
CVE-2026-87113
6.3 MEDIUM

Tanium addressed an improper access controls vulnerability in Threat Response.

Sep 16, 2026
CVE-2026-87076
6.5 MEDIUM

Tanium addressed an information disclosure vulnerability in Discover.

Sep 16, 2026
CVE-2026-62949
6.5 MEDIUM

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior …

Sep 16, 2026
CVE-2026-92417
6.5 MEDIUM

A vulnerability was found in Open5GS up to 2.8.0. This affects the function ogs_pfcp_parse_volume_measurement in the library lib/pfcp/types.c of the component PFCP Handler. The manipulation …

Sep 16, 2026
CVE-2026-81176
5.3 MEDIUM

Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. Prior to 5.9.2, devalue.parse does not reject …

Sep 16, 2026
CVE-2026-75025
4.7 MEDIUM

Mattermost Desktop App versions <=6.2 6.2.2.0 Fixed an issue where Mattermost Desktop did not sufficiently restrict server-rendered content from accessing local or private network resources. …

Sep 16, 2026
CVE-2026-73462
6.5 MEDIUM

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can …

Sep 16, 2026
CVE-2026-73457
5.3 MEDIUM

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in …

Sep 16, 2026
CVE-2026-73443
4.7 MEDIUM

On affected platforms running Arista EOS with VRRPv2 IP-AH authentication configured, an unauthenticated attacker within the same layer 2 network segment on which VRRP is …

Sep 16, 2026
CVE-2026-63225
4.4 MEDIUM

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI …

Sep 16, 2026
CVE-2026-92605
6.5 MEDIUM

IRIS through 2.4.29 fails to properly validate case authorization in comment listing endpoints for notes, tasks, IOCs, assets, and evidence items. Attackers with access to …

Sep 16, 2026
CVE-2026-92416
4.3 MEDIUM

A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component …

Sep 16, 2026
CVE-2026-92413
4.3 MEDIUM

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the …

Sep 16, 2026
CVE-2026-84397
5.4 MEDIUM

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into …

Sep 16, 2026
CVE-2026-69147
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to …

Sep 16, 2026
CVE-2026-92603
6.5 MEDIUM

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and …

Sep 16, 2026
CVE-2026-92601
6.5 MEDIUM

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated …

Sep 16, 2026
CVE-2026-92600
6.5 MEDIUM

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC …

Sep 16, 2026
CVE-2026-92402
6.3 MEDIUM

A security flaw has been discovered in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This issue affects the function index of the file UserController.java of the component …

Sep 16, 2026
CVE-2026-86358
6.5 MEDIUM

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this …

Sep 16, 2026
CVE-2026-85732
4.7 MEDIUM

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link …

Sep 16, 2026
CVE-2026-84993
6.5 MEDIUM

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared …

Sep 16, 2026
CVE-2026-59944
6.1 MEDIUM

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass …

Sep 16, 2026
CVE-2026-57173
6.5 MEDIUM

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without …

Sep 16, 2026
CVE-2026-92615
6.6 MEDIUM

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, …

Sep 16, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.