CVE Database

132614+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81719
7.8 HIGH

openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy defaulted to WARN, so an unsigned/unverifiable non-built-in plugin was compiled and …

Aug 27, 2026
CVE-2026-81718
7.5 HIGH

openssl_encrypt versions before 1.4.9 use under-parameterized PBKDF2-HMAC-SHA256 with only 100,000 iterations to protect PQC keyfile private keys and 10,000 iterations for dual-encryption file-password verification. Attackers …

Aug 27, 2026
CVE-2026-81717
3.5 LOW

openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker …

Aug 27, 2026
CVE-2026-81716
5.2 MEDIUM

openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, which authorized file access using a bare string-prefix match. A sandboxed plugin …

Aug 27, 2026
CVE-2026-81715
3.3 LOW

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug …

Aug 27, 2026
CVE-2026-81714
7.0 HIGH

openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when binding a plugin-signing trust anchor. An operator who confirms a short (forgeable, …

Aug 27, 2026
CVE-2026-81707
9.8 CRITICAL

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification …

Aug 27, 2026
CVE-2026-81706
6.8 MEDIUM

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible until the …

Aug 27, 2026
CVE-2026-81705
7.5 HIGH

openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bundled short-option spellings (e.g. -apHunter2) …

Aug 27, 2026
CVE-2026-81704
7.5 HIGH

openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attackers can perform …

Aug 27, 2026
CVE-2026-81703
5.5 MEDIUM

openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metadata. Attackers can craft files with unencrypted embedded PQC …

Aug 27, 2026
CVE-2026-81702
9.8 CRITICAL

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can …

Aug 27, 2026
CVE-2026-81701
9.8 CRITICAL

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature …

Aug 27, 2026
CVE-2026-81700
9.8 CRITICAL

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, …

Aug 27, 2026
CVE-2026-81699
7.5 HIGH

openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during …

Aug 27, 2026
CVE-2026-81698
7.5 HIGH

openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block that interpolates untrusted metadata fields without quoting. Attackers can …

Aug 27, 2026
CVE-2026-81697
5.5 MEDIUM

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 contain a CWD-relative configuration file resolution flaw in crypt_settings.py, where CONFIG_FILE (originally the absolute per-user path ~/.crypt_settings.json) is …

Aug 27, 2026
CVE-2026-81696
3.3 LOW

openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info command. Attackers can craft malicious files containing escape …

Aug 27, 2026
CVE-2026-81695
3.3 LOW

openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-detection. Attackers can craft encrypted files with malicious key_id containing …

Aug 27, 2026
CVE-2026-81694
3.3 LOW

openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-GCM authenticated manifest) before printing them in the …

Aug 27, 2026
CVE-2026-81693
7.5 HIGH

openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers can supply crafted QR images with extremely large …

Aug 27, 2026
CVE-2026-81692
7.5 HIGH

openssl_encrypt (pip: openssl-encrypt) versions 1.4.8 and earlier fail to validate the 36-bit STREAMINFO total_samples field of FLAC files before using it to size an allocation …

Aug 27, 2026
CVE-2026-81691
7.5 HIGH

openssl_encrypt versions before 1.4.9 fail to validate server URLs in login and register_with_email functions, accepting unencrypted http:// URLs and unconfigured hosts. Attackers on the network …

Aug 27, 2026
CVE-2026-81690
7.3 HIGH

openssl-encrypt (pip package) before 1.4.9 contains a symlink-following flaw in its verify-usb v2 added-file allowlist scan. The scan enumerated the drive with rglob(), which in …

Aug 27, 2026
CVE-2026-81689
7.5 HIGH

openssl_encrypt versions before 1.4.9 derive the remote-pepper wrap key using unsalted HKDF-SHA256 or bare SHA-256 of the password, allowing identical keys across all users and …

Aug 27, 2026
CVE-2026-81688
7.5 HIGH

openssl_encrypt versions before 1.4.9 store an unkeyed SHA-256 hash of the plaintext in the cleartext file header metadata. Attackers can read this hash without the …

Aug 27, 2026
CVE-2026-81687
5.5 MEDIUM

openssl_encrypt versions before 1.4.9 fail to enforce a time ceiling on key derivation function iteration counts specified in file metadata. Attackers can craft files with …

Aug 27, 2026
CVE-2026-81686
6.2 MEDIUM

openssl_encrypt 1.4.x before 1.4.9 contains an optional D-Bus crypto service whose org.freedesktop.DBus.Properties.Set method performs neither a polkit authorization check nor value validation. Any local user …

Aug 27, 2026
CVE-2026-81685
3.3 LOW

openssl_encrypt versions before 1.4.9 fail to sanitize recovery-slot metadata in the desktop GUI, allowing attackers to inject control characters and line separators into the irreversible-removal …

Aug 27, 2026
CVE-2026-81684
6.2 MEDIUM

In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child process on the command line via …

Aug 27, 2026
CVE-2026-81683
8.4 HIGH

openssl_encrypt (pip package openssl-encrypt) versions 1.4.8 and earlier store an mTLS client private key in cleartext within a world-readable (0644) SharedPreferences file via the desktop …

Aug 27, 2026
CVE-2026-81682
6.2 MEDIUM

openssl_encrypt versions before 1.4.9 contain an insecure file permissions vulnerability in the desktop GUI that writes decrypted plaintext with world-readable default permissions. Attackers can read …

Aug 27, 2026
CVE-2026-81681
4.6 MEDIUM

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 advertise a portable USB workspace as an 'Encrypted USB Workspace' with AES-256-GCM encryption and write a marker declaring …

Aug 27, 2026
CVE-2026-81680
4.0 MEDIUM

openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re-encrypting the payload. Attackers can …

Aug 27, 2026
CVE-2026-81679
7.7 HIGH

OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent …

Aug 27, 2026
CVE-2026-81678
7.5 HIGH

AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo …

Aug 27, 2026
CVE-2026-81664
5.3 MEDIUM

The OpenFaaS gateway registers GET /system/telemetry in gateway/main.go and, when basic_auth is enabled, wraps each administrative /system/* handler in auth.DecorateWithBasicAuth. TelemetryHandler was left out of …

Aug 27, 2026
CVE-2026-81335
7.5 HIGH

Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared …

Aug 27, 2026
CVE-2026-81334
6.1 MEDIUM

darknet subscripts its layer array with an index taken from a configuration file without checking it against the array's length. The array is allocated in …

Aug 27, 2026
CVE-2026-81102
3.1 LOW

The Dash MCP server bound its listener to the loopback address but never checked the host a request named. src/mcp_server_dash.py constructed the server for its …

Aug 27, 2026
CVE-2026-81101
6.5 MEDIUM

The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute in src/cli.ts persisted the value given to its endpoint …

Aug 27, 2026
CVE-2026-81100
6.8 MEDIUM

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the …

Aug 27, 2026
CVE-2026-81099
6.8 MEDIUM

tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the …

Aug 27, 2026
CVE-2026-81098
9.1 CRITICAL

The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path …

Aug 27, 2026
CVE-2026-81097
8.4 HIGH

The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with replacements for the process-spawning methods on …

Aug 27, 2026
CVE-2026-81096
10.0 CRITICAL

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in …

Aug 27, 2026
CVE-2026-81095
6.8 MEDIUM

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the …

Aug 27, 2026
CVE-2026-81094
9.1 CRITICAL

The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts …

Aug 27, 2026
CVE-2026-81093
8.6 HIGH

The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/common/get_html_skeleton.ts validated the url argument with isValidHttpUrl from …

Aug 27, 2026
CVE-2026-81092
6.8 MEDIUM

mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in server/streamable_http.go and SSEServer.ServeHTTP in server/sse.go served any request arriving over a …

Aug 27, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.