CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-73839
4.6 MEDIUM

Administrative credentials may be exposed in plaintext within the Ebyte device's management interface, increasing the risk of credential compromise through visual or remote observation. This …

Aug 28, 2026
CVE-2026-73809
7.5 HIGH

A cleartext transmission of sensitive information vulnerability exists in certain Ebyte gateway products. The web management interface does not adequately protect sensitive communications using transport-layer …

Aug 28, 2026
CVE-2026-73125
9.8 CRITICAL

Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive configuration information, …

Aug 28, 2026
CVE-2026-71396
5.4 MEDIUM

Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.

Aug 28, 2026
CVE-2026-71187
9.8 CRITICAL

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass …

Aug 28, 2026
CVE-2026-69658
9.8 CRITICAL

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging …

Aug 28, 2026
CVE-2026-68967
6.5 MEDIUM

Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that could establish an arbitrary write …

Aug 28, 2026
CVE-2026-68929

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize …

Aug 28, 2026
CVE-2026-67560
7.5 HIGH

Bendix EC80 Brake ECU is vulnerable to a stack-based buffer overflow, which may allow an attacker to crash the ECU. A crafted payload can then …

Aug 28, 2026
CVE-2026-61783

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.14.0 through 4.14.6, an authenticated low-privilege …

Aug 28, 2026
CVE-2026-5706

In Bluetooth Mesh SDK 6.1.4 and earlier, malformed extended advertisements can trigger out-of-bounds writes leading to stack corruption and remote code execution. These messages must …

Aug 28, 2026
CVE-2026-54330
8.1 HIGH

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) …

Aug 28, 2026
CVE-2026-54085
7.1 HIGH

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.2.0 through 4.14.6, multiple active response …

Aug 28, 2026
CVE-2026-54084
5.3 MEDIUM

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.0.0 through 4.14.6, a malicious or …

Aug 28, 2026
CVE-2026-54083
8.1 HIGH

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The ip-customblock active response script contains a path …

Aug 28, 2026
CVE-2026-50152
9.1 CRITICAL

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails …

Aug 28, 2026
CVE-2026-44629
7.9 HIGH

Improper access control to the Synergis Softwire installation folder. This vulnerability affects Streamvault all-in-one appliances (SV-100E and SV-300E series) and Synergis Softwire installed on Windows …

Aug 28, 2026
CVE-2026-39944
8.8 HIGH

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the RADOS Gateway (RGW) protects …

Aug 28, 2026
CVE-2026-38350
7.5 HIGH

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

Aug 28, 2026
CVE-2026-38349
7.5 HIGH

An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image …

Aug 28, 2026
CVE-2026-38348
7.5 HIGH

An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.

Aug 28, 2026
CVE-2026-38347
7.5 HIGH

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted …

Aug 28, 2026
CVE-2026-38346
7.5 HIGH

An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video …

Aug 28, 2026
CVE-2026-38345

A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Aug 28, 2026
CVE-2026-38344
7.5 HIGH

A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted …

Aug 28, 2026
CVE-2026-38343
6.5 MEDIUM

An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.

Aug 28, 2026
CVE-2026-18965
8.8 HIGH

PayRange API is missing proper authorization on management endpoints, which allows verbose details of every device on the PayRange network to be publicly accessible, with …

Aug 28, 2026
CVE-2026-18717
7.4 HIGH

ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS …

Aug 28, 2026
CVE-2026-17610

In SiSDK v2026.6.0 and earlier, high network traffic loads can cause a dropped ACK leading to a denial of service. This is only present for …

Aug 28, 2026
CVE-2025-30156
8.9 HIGH

Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the CephX authentication protocol encrypts …

Aug 28, 2026
CVE-2026-81934
7.1 HIGH

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated …

Aug 27, 2026
CVE-2026-81931

Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the …

Aug 27, 2026
CVE-2026-81893
4.7 MEDIUM

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can …

Aug 27, 2026
CVE-2026-81838
7.1 HIGH

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 through 0.23 can allow a third party to …

Aug 27, 2026
CVE-2026-81834
6.3 MEDIUM

A weakness has been identified in RooCodeInc Roo-Code up to 3.51.1. Affected by this issue is the function ExecaTerminalProcess of the component README File Handler. …

Aug 27, 2026
CVE-2026-81833
5.5 MEDIUM

A security flaw has been discovered in RooCodeInc Roo-Code up to 3.51.1. Affected by this vulnerability is the function optimizeQuery of the file src/utils/helpers.ts of …

Aug 27, 2026
CVE-2026-81731
5.4 MEDIUM

Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description field of the Workspace Link doctype is declared with …

Aug 27, 2026
CVE-2026-81730
8.2 HIGH

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The …

Aug 27, 2026
CVE-2026-81729
6.5 MEDIUM

Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handling DELETE …

Aug 27, 2026
CVE-2026-81728
8.1 HIGH

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, …

Aug 27, 2026
CVE-2026-81530
5.6 MEDIUM

A weakness in the client-side encryption configuration surface of the MongoDB C# Driver causes sensitive key-management credential material supplied by the application to be reproduced …

Aug 27, 2026
CVE-2026-81529
7.1 HIGH

Improper neutralization of delimiters in connection-URL construction allows connection-option injection in the MongoDB C# Driver. When an application passes untrusted text into the driver's connection-URL …

Aug 27, 2026
CVE-2026-81528
5.4 MEDIUM

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write paths apply, so a value supplied as a replacement is …

Aug 27, 2026
CVE-2026-81527
6.5 MEDIUM

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver, in both aggregation expression and query filter translation. When …

Aug 27, 2026
CVE-2026-81526
6.5 MEDIUM

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding it in the request it sends to the server. …

Aug 27, 2026
CVE-2026-81525
8.1 HIGH

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for …

Aug 27, 2026
CVE-2026-81524
5.4 MEDIUM

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes …

Aug 27, 2026
CVE-2026-81523
4.4 MEDIUM

A missing input-validation issue in MongoDB libmongocrypt's automatic-encryption context setup allows a caller-supplied database identifier to be accepted without sanitization. The resulting impact is limited …

Aug 27, 2026
CVE-2026-81522
8.1 HIGH

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An application that builds a namespace …

Aug 27, 2026
CVE-2026-81521
6.5 MEDIUM

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name …

Aug 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.