CVE Database

132723+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-55182

LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli …

Aug 26, 2026
CVE-2026-45694
5.4 MEDIUM

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the …

Aug 26, 2026
CVE-2026-43621
8.1 HIGH

Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to …

Aug 26, 2026
CVE-2026-21810
4.4 MEDIUM

HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to …

Aug 26, 2026
CVE-2026-21809
3.9 LOW

HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an …

Aug 26, 2026
CVE-2026-16809

LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage …

Aug 26, 2026
CVE-2026-79921

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and …

Aug 26, 2026
CVE-2026-77573
3.5 LOW

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs …

Aug 26, 2026
CVE-2026-77507
5.3 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the …

Aug 26, 2026
CVE-2026-75415
7.5 HIGH

AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing …

Aug 26, 2026
CVE-2026-75414
9.8 CRITICAL

In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.

Aug 26, 2026
CVE-2026-75413
7.5 HIGH

DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any …

Aug 26, 2026
CVE-2026-75411
9.8 CRITICAL

JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs …

Aug 26, 2026
CVE-2026-75364
6.8 MEDIUM

Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via …

Aug 26, 2026
CVE-2026-75363
6.8 MEDIUM

An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.

Aug 26, 2026
CVE-2026-62326
6.5 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role …

Aug 26, 2026
CVE-2026-62249
4.3 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project …

Aug 26, 2026
CVE-2026-61792
7.7 HIGH

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their …

Aug 26, 2026
CVE-2026-61790
4.4 MEDIUM

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure …

Aug 26, 2026
CVE-2026-55228
8.1 HIGH

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the …

Aug 26, 2026
CVE-2026-55227
4.3 MEDIUM

Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the …

Aug 26, 2026
CVE-2026-52473
4.3 MEDIUM

An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.

Aug 26, 2026
CVE-2026-52103
9.8 CRITICAL

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context …

Aug 26, 2026
CVE-2026-39275
6.1 MEDIUM

Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components

Aug 26, 2026
CVE-2026-15973

LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission …

Aug 26, 2026
CVE-2025-61480
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP …

Aug 26, 2026
CVE-2025-61479
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC …

Aug 26, 2026
CVE-2025-61478
7.5 HIGH

An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN …

Aug 26, 2026
CVE-2025-51679
9.1 CRITICAL

An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.

Aug 26, 2026
CVE-2025-51675
7.5 HIGH

An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial …

Aug 26, 2026
CVE-2026-79939
5.8 MEDIUM

Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially …

Aug 26, 2026
CVE-2026-79938
7.6 HIGH

Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, …

Aug 26, 2026
CVE-2026-77652
7.8 HIGH

A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette …

Aug 26, 2026
CVE-2026-77508
3.5 LOW

Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to …

Aug 26, 2026
CVE-2026-75601
4.3 MEDIUM

Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features …

Aug 26, 2026
CVE-2026-75334
9.8 CRITICAL

The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through …

Aug 26, 2026
CVE-2026-75327
9.8 CRITICAL

In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:

Aug 26, 2026
CVE-2026-74774
5.9 MEDIUM

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Aug 26, 2026
CVE-2026-74771
6.5 MEDIUM

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit …

Aug 26, 2026
CVE-2026-74770
8.8 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-71172
4.3 MEDIUM

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit …

Aug 26, 2026
CVE-2026-71054
6.5 MEDIUM

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network …

Aug 26, 2026
CVE-2026-68863
7.5 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Aug 26, 2026
CVE-2026-68861
8.8 HIGH

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low …

Aug 26, 2026
CVE-2026-68000
9.8 CRITICAL

The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through …

Aug 26, 2026
CVE-2026-67275
5.3 MEDIUM

Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Aug 26, 2026
CVE-2026-66003

Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows …

Aug 26, 2026
CVE-2026-60004
9.8 CRITICAL KEV

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Aug 26, 2026
CVE-2026-56547
3.5 LOW

The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address …

Aug 26, 2026
CVE-2026-54245

Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable …

Aug 26, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.