CVE Database

52018+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-49799
6.5 MEDIUM

Uncontrolled resource consumption in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-49794
4.6 MEDIUM

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.

Jul 14, 2026
CVE-2026-49180
5.5 MEDIUM

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-49174
6.1 MEDIUM

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Jul 14, 2026
CVE-2026-49168
6.8 MEDIUM

Integer overflow or wraparound in Windows Storage Spaces Direct allows an unauthorized attacker to elevate privileges with a physical attack.

Jul 14, 2026
CVE-2026-49167
4.7 MEDIUM

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Jul 14, 2026
CVE-2026-47282
6.5 MEDIUM

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-45496
5.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

Jul 14, 2026
CVE-2026-44806
5.3 MEDIUM

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Jul 14, 2026
CVE-2026-41087
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-40422
5.5 MEDIUM

Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-36214
5.4 MEDIUM

osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip …

Jul 14, 2026
CVE-2026-34349
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Media allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-34348
6.5 MEDIUM

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

Jul 14, 2026
CVE-2026-34346
5.5 MEDIUM

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-34328
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-33842
5.5 MEDIUM

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Jul 14, 2026
CVE-2026-15702
6.3 MEDIUM

A security vulnerability has been detected in tamagui up to 2.3.0. This affects the function updateConfig of the file code/core/web/src/config.ts. Such manipulation leads to improperly …

Jul 14, 2026
CVE-2026-15700
4.7 MEDIUM

A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of the file include/zip.class.php of the component Album …

Jul 14, 2026
CVE-2026-62644
6.4 MEDIUM

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which …

Jul 14, 2026
CVE-2026-62642
4.3 MEDIUM

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service …

Jul 14, 2026
CVE-2026-62641
4.3 MEDIUM

In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

Jul 14, 2026
CVE-2026-60119
5.4 MEDIUM

Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by …

Jul 14, 2026
CVE-2026-60118
5.3 MEDIUM

Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs …

Jul 14, 2026
CVE-2026-59840
4.3 MEDIUM

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all …

Jul 14, 2026
CVE-2026-59839
5.5 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 …

Jul 14, 2026
CVE-2026-59837
6.6 MEDIUM

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 …

Jul 14, 2026
CVE-2026-59203
5.3 MEDIUM

Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow's EPS parser in PIL/EpsImagePlugin.py accepts a negative byte count in the %%BeginBinary directive, allowing …

Jul 14, 2026
CVE-2026-59198
6.5 MEDIUM

Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's TGA RLE encoder reads past its packed row buffer when saving a mode 1 …

Jul 14, 2026
CVE-2026-23573
6.1 MEDIUM

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS …

Jul 14, 2026
CVE-2026-15699
6.3 MEDIUM

A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. …

Jul 14, 2026
CVE-2026-15698
6.3 MEDIUM

A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the …

Jul 14, 2026
CVE-2026-15697
6.3 MEDIUM

A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. …

Jul 14, 2026
CVE-2026-11944
6.5 MEDIUM

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary …

Jul 14, 2026
CVE-2025-43892
4.3 MEDIUM

A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all …

Jul 14, 2026
CVE-2026-58478
6.5 MEDIUM

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP …

Jul 14, 2026
CVE-2026-58475
6.1 MEDIUM

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScript by supplying malicious script …

Jul 14, 2026
CVE-2026-14902
4.0 MEDIUM

An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.

Jul 14, 2026
CVE-2026-10670
5.5 MEDIUM

The CONFIG_USERSPACE verification handler for the k_thread_name_copy() system call (z_vrfy_k_thread_name_copy() in kernel/thread.c) calls k_object_find() on the caller-supplied thread pointer and then dereferences the returned struct …

Jul 14, 2026
CVE-2026-62393
4.3 MEDIUM

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kylin. Improper authorization in job information retrieval, where an attacker may get access to unauthorized …

Jul 14, 2026
CVE-2026-49488
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenMeetings: from 5.0.0 before 9.1.0. An …

Jul 14, 2026
CVE-2026-15719
5.4 MEDIUM

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This …

Jul 14, 2026
CVE-2026-15718
4.3 MEDIUM

We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This …

Jul 14, 2026
CVE-2026-9341
4.3 MEDIUM

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up …

Jul 14, 2026
CVE-2026-12478
4.8 MEDIUM

The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block, leaving unmasked server-to-client frames unprotected. A malicious …

Jul 14, 2026
CVE-2025-40945
6.7 MEDIUM

A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter …

Jul 14, 2026
CVE-2026-8384
5.3 MEDIUM

In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admin/secret.txt instead of the expected: /admin/secret.txt Jetty itself is …

Jul 14, 2026
CVE-2026-6790
5.3 MEDIUM

In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what provided in …

Jul 14, 2026
CVE-2026-13699
4.3 MEDIUM

In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request …

Jul 14, 2026
CVE-2026-12606
5.3 MEDIUM

Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveraged to perform HTTP request …

Jul 14, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.