CVE Database

57789+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10204
6.3 MEDIUM

A weakness has been identified in OFCMS 1.1.3. The affected element is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SysUserController.java of the component JSON Query Interface. …

Jun 1, 2026
CVE-2026-10203
6.3 MEDIUM

A security flaw has been discovered in OFCMS 1.1.3. Impacted is the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemParamController.java of the component JSON Query Interface. The …

Jun 1, 2026
CVE-2026-10202
6.3 MEDIUM

A vulnerability was identified in OFCMS 1.1.3. This issue affects the function Query of the file \ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\system\SystemDictController.java of the component JSON Query Interface. The manipulation …

Jun 1, 2026
CVE-2026-10200
5.3 MEDIUM

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing …

May 31, 2026
CVE-2026-48210
5.7 MEDIUM

An improper default configuration in OTRS 2026.3.1 causes ticket article forwarding actions to enforce the “Is visible for customer” flag by default and prevent users …

May 31, 2026
CVE-2026-10194
6.3 MEDIUM

A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation …

May 31, 2026
CVE-2026-10193
6.3 MEDIUM

A security flaw has been discovered in OFCMS up to 1.1.3. The impacted element is the function Query of the file ofcms-admin\src\main\java\com\ofsoft\cms\admin\controller\ComnController.java of the component …

May 31, 2026
CVE-2026-10190
6.5 MEDIUM

A vulnerability was found in Tenda W12 3.0.0.7(4763). This issue affects the function cgiSysWebTimeoutSet of the file /bin/httpd of the component Web Management Interface. The …

May 31, 2026
CVE-2026-10182
6.3 MEDIUM

A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. The impacted element is the function formWlanSetup of the file /goform/formWlanSetup. Executing a manipulation of the argument …

May 31, 2026
CVE-2026-10180
6.3 MEDIUM

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. Impacted is the function formSysCmd of the file /goform/formSysCmd. Such manipulation of the argument sysCmd leads …

May 31, 2026
CVE-2026-10177
6.3 MEDIUM

A security vulnerability has been detected in Aider-AI Aider 0.86.3. This affects the function requests.get of the file api_docs.py of the component AWS EC2 Metadata …

May 31, 2026
CVE-2026-10176
6.3 MEDIUM

A weakness has been identified in Aider-AI Aider 0.86.3. Affected by this issue is some unknown functionality of the component Code Generation Workflow. Executing a …

May 31, 2026
CVE-2026-10175
6.3 MEDIUM

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component …

May 31, 2026
CVE-2026-10174
6.3 MEDIUM

A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation …

May 31, 2026
CVE-2026-10173
4.3 MEDIUM

A weakness has been identified in Orthanc Explorer 2 up to 1.12.0. The impacted element is an unknown function of the file WebApplication/src/components/StudyList.vue of the …

May 31, 2026
CVE-2026-10172
6.3 MEDIUM

A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of …

May 31, 2026
CVE-2026-10171
4.7 MEDIUM

A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument …

May 31, 2026
CVE-2026-10170
6.3 MEDIUM

A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation …

May 31, 2026
CVE-2026-10168
6.3 MEDIUM

A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The …

May 31, 2026
CVE-2026-8382
5.3 MEDIUM

The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.1. This is due to …

May 31, 2026
CVE-2026-10166
6.3 MEDIUM

A vulnerability was determined in Edimax BR-6478AC 1.23. The affected element is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Handler. …

May 31, 2026
CVE-2026-10156
4.3 MEDIUM

A vulnerability was determined in Open5GS up to 2.7.7. This affects the function handle_amf_info in the library /lib/sbi/nnrf-handler.c of the component nf-instances Endpoint. Executing a …

May 31, 2026
CVE-2026-10155
4.7 MEDIUM

A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component …

May 31, 2026
CVE-2026-10154
4.3 MEDIUM

A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the …

May 31, 2026
CVE-2026-10153
4.3 MEDIUM

A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument …

May 30, 2026
CVE-2026-10152
6.3 MEDIUM

A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. …

May 30, 2026
CVE-2026-10127
6.3 MEDIUM

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This …

May 30, 2026
CVE-2026-8594
6.2 MEDIUM

Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific line …

May 30, 2026
CVE-2018-25423
6.2 MEDIUM

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized input string. Attackers can paste …

May 30, 2026
CVE-2018-25421
6.5 MEDIUM

Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send …

May 30, 2026
CVE-2026-10117
4.3 MEDIUM

A weakness has been identified in Open5GS up to 2.7.7. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead …

May 30, 2026
CVE-2026-10116
4.3 MEDIUM

A security flaw has been discovered in Open5GS up to 2.7.7. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications …

May 30, 2026
CVE-2026-10115
4.3 MEDIUM

A vulnerability was identified in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such …

May 30, 2026
CVE-2026-10114
4.3 MEDIUM

A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared …

May 30, 2026
CVE-2026-10113
4.3 MEDIUM

A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the library lib/sbi/nnrf-handler.c of the component Shared …

May 30, 2026
CVE-2026-5071
6.1 MEDIUM

The SocketCAN implementation validates the length of a user-provided buffer containing a socketcan_frame object using only a NET_ASSERT statement in zcan_sendto_ctx() before dereferencing it in …

May 30, 2026
CVE-2026-48840
5.3 MEDIUM

Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.

May 30, 2026
CVE-2026-9831
6.3 MEDIUM

A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with …

May 29, 2026
CVE-2026-48811
4.3 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete …

May 29, 2026
CVE-2026-48810
4.3 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the …

May 29, 2026
CVE-2026-45352
5.3 MEDIUM

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. …

May 29, 2026
CVE-2026-45294
5.3 MEDIUM

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses …

May 29, 2026
CVE-2026-45149
6.5 MEDIUM

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. …

May 29, 2026
CVE-2026-44640
4.5 MEDIUM

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during …

May 29, 2026
CVE-2026-44287
6.3 MEDIUM

FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.test(code). JavaScript syntax …

May 29, 2026
CVE-2026-42500
5.3 MEDIUM

Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.

May 29, 2026
CVE-2026-34127
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the …

May 29, 2026
CVE-2026-49386
6.5 MEDIUM

In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas

May 29, 2026
CVE-2026-49385
6.5 MEDIUM

In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts

May 29, 2026
CVE-2026-49384
6.1 MEDIUM

In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible

May 29, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.