CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-88049
5.5 MEDIUM

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but …

Sep 10, 2026
CVE-2026-88046
5.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject …

Sep 10, 2026
CVE-2026-52097
6.8 MEDIUM

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

Sep 10, 2026
CVE-2026-88940
5.3 MEDIUM

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host …

Sep 10, 2026
CVE-2026-88938
6.5 MEDIUM

knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source …

Sep 10, 2026
CVE-2026-88015
5.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true …

Sep 10, 2026
CVE-2026-88014
6.3 MEDIUM

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend …

Sep 10, 2026
CVE-2026-88012
5.3 MEDIUM

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the …

Sep 10, 2026
CVE-2026-87913
5.9 MEDIUM

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source …

Sep 10, 2026
CVE-2026-87912
5.9 MEDIUM

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private …

Sep 10, 2026
CVE-2026-81052
6.8 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit …

Sep 10, 2026
CVE-2026-81051
6.6 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could …

Sep 10, 2026
CVE-2026-81049
4.4 MEDIUM

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit …

Sep 10, 2026
CVE-2026-88898
6.5 MEDIUM

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into …

Sep 10, 2026
CVE-2026-88897
5.9 MEDIUM

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or …

Sep 10, 2026
CVE-2026-88006
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for …

Sep 10, 2026
CVE-2026-88005
6.5 MEDIUM

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for …

Sep 10, 2026
CVE-2026-85310
6.5 MEDIUM

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

Sep 10, 2026
CVE-2026-81793
6.5 MEDIUM

Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions.

Sep 10, 2026
CVE-2026-81791
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

Sep 10, 2026
CVE-2026-81788
6.3 MEDIUM

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

Sep 10, 2026
CVE-2026-81787
6.5 MEDIUM

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

Sep 10, 2026
CVE-2026-81785
6.5 MEDIUM

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

Sep 10, 2026
CVE-2026-81782
6.5 MEDIUM

Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.

Sep 10, 2026
CVE-2026-81275
6.5 MEDIUM

Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions.

Sep 10, 2026
CVE-2026-78536
6.5 MEDIUM

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

Sep 10, 2026
CVE-2026-66674
5.6 MEDIUM

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

Sep 10, 2026
CVE-2026-66632
6.5 MEDIUM

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

Sep 10, 2026
CVE-2026-15461
5.3 MEDIUM

The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match helper (drivers/gnss/gnss_nmea0183_match.c) …

Sep 10, 2026
CVE-2026-88896
5.3 MEDIUM

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) …

Sep 10, 2026
CVE-2026-88894
5.4 MEDIUM

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, …

Sep 10, 2026
CVE-2026-88892
5.0 MEDIUM

OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data importer fetches a caller-supplied URL with plain …

Sep 10, 2026
CVE-2026-88884
5.8 MEDIUM

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm …

Sep 10, 2026
CVE-2026-88878
5.3 MEDIUM

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings …

Sep 10, 2026
CVE-2026-88875
4.3 MEDIUM

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user …

Sep 10, 2026
CVE-2026-88871
4.3 MEDIUM

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script reads users_id and ExtraSubscribers …

Sep 10, 2026
CVE-2026-88860
6.3 MEDIUM

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific …

Sep 10, 2026
CVE-2026-88790
4.8 MEDIUM

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File …

Sep 10, 2026
CVE-2026-45763
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when …

Sep 10, 2026
CVE-2026-12683
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: …

Sep 10, 2026
CVE-2026-12682
5.4 MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: …

Sep 10, 2026
CVE-2026-9161
5.3 MEDIUM

Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about …

Sep 10, 2026
CVE-2026-88038
4.8 MEDIUM

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie …

Sep 10, 2026
CVE-2026-85544
5.2 MEDIUM

There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products. This could allow attackers to forge M1 cards.

Sep 10, 2026
CVE-2026-85543
4.3 MEDIUM

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.

Sep 10, 2026
CVE-2026-88859
6.3 MEDIUM

A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. …

Sep 10, 2026
CVE-2026-84828
6.5 MEDIUM

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' …

Sep 10, 2026
CVE-2026-5399
6.4 MEDIUM

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profile settings in versions up to and …

Sep 10, 2026
CVE-2026-15889
6.4 MEDIUM

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 …

Sep 10, 2026
CVE-2026-88288
6.5 MEDIUM

GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with valid web credentials to read arbitrary files accessible to …

Sep 10, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.