CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81486
5.3 MEDIUM

A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. …

Aug 27, 2026
CVE-2026-81485
5.3 MEDIUM

A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component …

Aug 27, 2026
CVE-2026-19398

“unsupported-when-assigned.” An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local administrator to cause a system crash (BSOD) …

Aug 27, 2026
CVE-2026-81421
7.3 HIGH

A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the …

Aug 27, 2026
CVE-2026-80183

In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a …

Aug 27, 2026
CVE-2026-47874
5.3 MEDIUM

The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount …

Aug 27, 2026
CVE-2026-47863
5.9 MEDIUM

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - …

Aug 27, 2026
CVE-2026-47862
5.4 MEDIUM

An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to …

Aug 27, 2026
CVE-2026-47861
6.3 MEDIUM

An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an …

Aug 27, 2026
CVE-2026-47860
6.5 MEDIUM

An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single …

Aug 27, 2026
CVE-2026-47859
5.4 MEDIUM

RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an …

Aug 27, 2026
CVE-2026-47857
5.9 MEDIUM

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - …

Aug 27, 2026
CVE-2026-47856
6.3 MEDIUM

Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with …

Aug 27, 2026
CVE-2026-47852
7.5 HIGH

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI …

Aug 27, 2026
CVE-2026-47851
7.5 HIGH

Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI …

Aug 27, 2026
CVE-2026-47850
4.3 MEDIUM

Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. …

Aug 27, 2026
CVE-2026-47845
5.3 MEDIUM

In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, …

Aug 27, 2026
CVE-2026-81203
7.3 HIGH

A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of …

Aug 26, 2026
CVE-2026-80158
5.5 MEDIUM

A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when …

Aug 26, 2026
CVE-2026-75340
9.1 CRITICAL

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).

Aug 26, 2026
CVE-2026-75338
9.8 CRITICAL

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The …

Aug 26, 2026
CVE-2026-75336
9.8 CRITICAL

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.

Aug 26, 2026
CVE-2026-75332
9.1 CRITICAL

Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

Aug 26, 2026
CVE-2026-75330
9.8 CRITICAL

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through …

Aug 26, 2026
CVE-2026-69129

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated …

Aug 26, 2026
CVE-2026-65956

KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public …

Aug 26, 2026
CVE-2026-47666
7.6 HIGH

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font …

Aug 26, 2026
CVE-2026-47665
8.7 HIGH

Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, …

Aug 26, 2026
CVE-2026-21808
4.1 MEDIUM

HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker …

Aug 26, 2026
CVE-2026-21807
3.9 LOW

HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

Aug 26, 2026
CVE-2026-18823

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 26, 2026
CVE-2025-62341
3.7 LOW

HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain …

Aug 26, 2026
CVE-2026-81202
7.3 HIGH

A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD …

Aug 26, 2026
CVE-2026-77611
7.1 HIGH

SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested …

Aug 26, 2026
CVE-2026-77368
7.6 HIGH

SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a …

Aug 26, 2026
CVE-2026-77317
8.1 HIGH

SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a …

Aug 26, 2026
CVE-2026-77298

SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly …

Aug 26, 2026
CVE-2026-75333
7.5 HIGH

yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path …

Aug 26, 2026
CVE-2026-75331
4.6 MEDIUM

tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type …

Aug 26, 2026
CVE-2026-75329
9.8 CRITICAL

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project …

Aug 26, 2026
CVE-2026-75328
7.5 HIGH

In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:

Aug 26, 2026
CVE-2026-65930

LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.

Aug 26, 2026
CVE-2026-65647

Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.

Aug 26, 2026
CVE-2026-65646

Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.

Aug 26, 2026
CVE-2026-65642

Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.

Aug 26, 2026
CVE-2026-65641

A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.

Aug 26, 2026
CVE-2026-64632

A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.

Aug 26, 2026
CVE-2026-63360

LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the …

Aug 26, 2026
CVE-2026-61617
7.7 HIGH

Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not …

Aug 26, 2026
CVE-2026-58070

A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.